Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe

Overview

General Information

Sample Name:Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
Analysis ID:625814
MD5:717fc8318eb370b1e8ae630af9fe431d
SHA1:842ee97ed218857603188de6831afcc9919addd6
SHA256:6035a6b2488b6c073d4b1cda9c9879e207b73e94c3551624667e59cc8719dd01
Tags:exeNanoCore
Infos:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sigma detected: NanoCore
Yara detected AntiVM3
Detected Nanocore Rat
Antivirus detection for URL or domain
Yara detected Nanocore RAT
Snort IDS alert for network traffic
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
.NET source code contains potential unpacker
.NET source code contains method to dynamically call methods (often used by packers)
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses dynamic DNS services
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Creates processes with suspicious names
IP address seen in connection with other malware
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Detected TCP or UDP traffic on non-standard ports
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • cleanup
{"Version": "1.2.2.0", "Mutex": "fe56abb4-cb76-44f1-89b4-7bb11730", "Group": "Default", "Domain1": "deranano2.ddns.net", "Port": 1187, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
SourceRuleDescriptionAuthorStrings
00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0xff8d:$x1: NanoCore.ClientPluginHost
  • 0xffca:$x2: IClientNetworkHost
  • 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
    00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
    • 0xfcf5:$a: NanoCore
    • 0xfd05:$a: NanoCore
    • 0xff39:$a: NanoCore
    • 0xff4d:$a: NanoCore
    • 0xff8d:$a: NanoCore
    • 0xfd54:$b: ClientPlugin
    • 0xff56:$b: ClientPlugin
    • 0xff96:$b: ClientPlugin
    • 0xfe7b:$c: ProjectData
    • 0x10882:$d: DESCrypto
    • 0x1824e:$e: KeepAlive
    • 0x1623c:$g: LogClientMessage
    • 0x12437:$i: get_Connected
    • 0x10bb8:$j: #=q
    • 0x10be8:$j: #=q
    • 0x10c04:$j: #=q
    • 0x10c34:$j: #=q
    • 0x10c50:$j: #=q
    • 0x10c6c:$j: #=q
    • 0x10c9c:$j: #=q
    • 0x10cb8:$j: #=q
    00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0xff8d:$x1: NanoCore.ClientPluginHost
    • 0xffca:$x2: IClientNetworkHost
    • 0x13afd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
    00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
      Click to see the 19 entries
      SourceRuleDescriptionAuthorStrings
      0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
      • 0xe38d:$x1: NanoCore.ClientPluginHost
      • 0xe3ca:$x2: IClientNetworkHost
      • 0x11efd:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
      0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
      • 0xe105:$x1: NanoCore Client.exe
      • 0xe38d:$x2: NanoCore.ClientPluginHost
      • 0xf9c6:$s1: PluginCommand
      • 0xf9ba:$s2: FileCommand
      • 0x1086b:$s3: PipeExists
      • 0x16622:$s4: PipeCreated
      • 0xe3b7:$s5: IClientLoggingHost
      0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpackJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
        0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpackMALWARE_Win_NanoCoreDetects NanoCoreditekSHen
        • 0xe0f5:$x1: NanoCore Client
        • 0xe105:$x1: NanoCore Client
        • 0xe34d:$x2: NanoCore.ClientPlugin
        • 0xe38d:$x3: NanoCore.ClientPluginHost
        • 0xe342:$i1: IClientApp
        • 0xe363:$i2: IClientData
        • 0xe36f:$i3: IClientNetwork
        • 0xe37e:$i4: IClientAppHost
        • 0xe3a7:$i5: IClientDataHost
        • 0xe3b7:$i6: IClientLoggingHost
        • 0xe3ca:$i7: IClientNetworkHost
        • 0xe3dd:$i8: IClientUIHost
        • 0xe3eb:$i9: IClientNameObjectCollection
        • 0xe407:$i10: IClientReadOnlyNameObjectCollection
        • 0xe154:$s1: ClientPlugin
        • 0xe356:$s1: ClientPlugin
        • 0xe84a:$s2: EndPoint
        • 0xe853:$s3: IPAddress
        • 0xe85d:$s4: IPEndPoint
        • 0x10293:$s6: get_ClientSettings
        • 0x10837:$s7: get_Connected
        0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpackNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
        • 0xe0f5:$a: NanoCore
        • 0xe105:$a: NanoCore
        • 0xe339:$a: NanoCore
        • 0xe34d:$a: NanoCore
        • 0xe38d:$a: NanoCore
        • 0xe154:$b: ClientPlugin
        • 0xe356:$b: ClientPlugin
        • 0xe396:$b: ClientPlugin
        • 0xe27b:$c: ProjectData
        • 0xec82:$d: DESCrypto
        • 0x1664e:$e: KeepAlive
        • 0x1463c:$g: LogClientMessage
        • 0x10837:$i: get_Connected
        • 0xefb8:$j: #=q
        • 0xefe8:$j: #=q
        • 0xf004:$j: #=q
        • 0xf034:$j: #=q
        • 0xf050:$j: #=q
        • 0xf06c:$j: #=q
        • 0xf09c:$j: #=q
        • 0xf0b8:$j: #=q
        Click to see the 40 entries

        AV Detection

        barindex
        Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, ProcessId: 6648, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

        E-Banking Fraud

        barindex
        Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, ProcessId: 6648, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

        Stealing of Sensitive Information

        barindex
        Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, ProcessId: 6648, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

        Remote Access Functionality

        barindex
        Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, ProcessId: 6648, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
        Timestamp:192.168.2.3212.193.30.2044975411872025019 05/13/22-08:08:00.468391
        SID:2025019
        Source Port:49754
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985411872025019 05/13/22-08:09:21.317521
        SID:2025019
        Source Port:49854
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044980111872025019 05/13/22-08:08:29.760918
        SID:2025019
        Source Port:49801
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044982111872025019 05/13/22-08:08:42.572616
        SID:2025019
        Source Port:49821
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:212.193.30.204192.168.2.31187497432841753 05/13/22-08:07:41.912295
        SID:2841753
        Source Port:1187
        Destination Port:49743
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975711872025019 05/13/22-08:08:08.371746
        SID:2025019
        Source Port:49757
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:212.193.30.204192.168.2.31187497542810290 05/13/22-08:08:01.239966
        SID:2810290
        Source Port:1187
        Destination Port:49754
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044982311872816766 05/13/22-08:08:50.618349
        SID:2816766
        Source Port:49823
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044974211872816766 05/13/22-08:07:36.524732
        SID:2816766
        Source Port:49742
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985211872816766 05/13/22-08:09:10.204690
        SID:2816766
        Source Port:49852
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044974611872816766 05/13/22-08:07:48.002664
        SID:2816766
        Source Port:49746
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975811872816766 05/13/22-08:08:17.137563
        SID:2816766
        Source Port:49758
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044976811872816766 05/13/22-08:08:24.638697
        SID:2816766
        Source Port:49768
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985311872816718 05/13/22-08:09:16.220396
        SID:2816718
        Source Port:49853
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044982311872025019 05/13/22-08:08:48.802408
        SID:2025019
        Source Port:49823
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044974611872025019 05/13/22-08:07:47.181678
        SID:2025019
        Source Port:49746
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044974211872025019 05/13/22-08:07:35.302011
        SID:2025019
        Source Port:49742
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985211872025019 05/13/22-08:09:09.270895
        SID:2025019
        Source Port:49852
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044980111872816766 05/13/22-08:08:30.710594
        SID:2816766
        Source Port:49801
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975711872816766 05/13/22-08:08:10.114903
        SID:2816766
        Source Port:49757
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044983311872025019 05/13/22-08:08:55.683074
        SID:2025019
        Source Port:49833
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975411872816766 05/13/22-08:08:02.678142
        SID:2816766
        Source Port:49754
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985311872025019 05/13/22-08:09:15.326471
        SID:2025019
        Source Port:49853
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044982111872816766 05/13/22-08:08:43.505269
        SID:2816766
        Source Port:49821
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044984811872816766 05/13/22-08:09:04.076097
        SID:2816766
        Source Port:49848
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044974311872025019 05/13/22-08:07:41.882179
        SID:2025019
        Source Port:49743
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044981511872816766 05/13/22-08:08:36.858197
        SID:2816766
        Source Port:49815
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044985311872816766 05/13/22-08:09:16.220396
        SID:2816766
        Source Port:49853
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975311872816766 05/13/22-08:07:55.099091
        SID:2816766
        Source Port:49753
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975311872025019 05/13/22-08:07:53.749457
        SID:2025019
        Source Port:49753
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044976811872025019 05/13/22-08:08:23.663433
        SID:2025019
        Source Port:49768
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044983311872816766 05/13/22-08:08:56.775852
        SID:2816766
        Source Port:49833
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975811872025019 05/13/22-08:08:15.665656
        SID:2025019
        Source Port:49758
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044975811872816718 05/13/22-08:08:16.194877
        SID:2816718
        Source Port:49758
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044981511872025019 05/13/22-08:08:36.042332
        SID:2025019
        Source Port:49815
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.3212.193.30.2044984811872025019 05/13/22-08:09:02.275060
        SID:2025019
        Source Port:49848
        Destination Port:1187
        Protocol:TCP
        Classtype:A Network Trojan was detected

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpackMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "fe56abb4-cb76-44f1-89b4-7bb11730", "Group": "Default", "Domain1": "deranano2.ddns.net", "Port": 1187, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeVirustotal: Detection: 37%Perma Link
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeReversingLabs: Detection: 43%
        Source: deranano2.ddns.netAvira URL Cloud: Label: malware
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTR
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJoe Sandbox ML: detected
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpackAvira: Label: TR/Dropper.MSIL.Gen7
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpackAvira: Label: TR/Dropper.MSIL.Gen7
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpackAvira: Label: TR/Dropper.MSIL.Gen7
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpackAvira: Label: TR/Dropper.MSIL.Gen7
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpackAvira: Label: TR/Dropper.MSIL.Gen7
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

        Networking

        barindex
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49742 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49742 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49743 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2841753 ETPRO TROJAN NanoCore RAT Keep-Alive Beacon (Inbound) 212.193.30.204:1187 -> 192.168.2.3:49743
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49746 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49746 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49753 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49753 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49754 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2810290 ETPRO TROJAN NanoCore RAT Keepalive Response 1 212.193.30.204:1187 -> 192.168.2.3:49754
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49754 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49757 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49757 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49758 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49758 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816718 ETPRO TROJAN NanoCore RAT Keep-Alive Beacon 192.168.2.3:49758 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49768 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49768 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49801 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49801 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49815 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49815 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49821 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49821 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49823 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49823 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49833 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49833 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49848 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49848 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49852 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49852 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49853 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816766 ETPRO TROJAN NanoCore RAT CnC 7 192.168.2.3:49853 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2816718 ETPRO TROJAN NanoCore RAT Keep-Alive Beacon 192.168.2.3:49853 -> 212.193.30.204:1187
        Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.3:49854 -> 212.193.30.204:1187
        Source: Malware configuration extractorURLs:
        Source: Malware configuration extractorURLs: deranano2.ddns.net
        Source: unknownDNS query: name: deranano2.ddns.net
        Source: Joe Sandbox ViewASN Name: SPD-NETTR SPD-NETTR
        Source: Joe Sandbox ViewIP Address: 212.193.30.204 212.193.30.204
        Source: global trafficTCP traffic: 192.168.2.3:49742 -> 212.193.30.204:1187
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252732703.0000000005E06000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://en.w
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://fontfabrik.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersB
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comF
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comFgN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comalsd
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comasva0N
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comdko
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comessedqN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comgrita
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comnN7
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.como
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comoJN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255061936.0000000005E08000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255166513.0000000005E07000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn=
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255166513.0000000005E07000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn?
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.264426212.0000000005E30000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/n
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/&N
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/)N
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/CN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/JN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/gN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/;N
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/nN7
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/qN
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252501913.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com=
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253293625.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.come
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253293625.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.comiv;b
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252501913.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.comt
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
        Source: unknownDNS traffic detected: queries for: deranano2.ddns.net

        E-Banking Fraud

        barindex
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTR

        System Summary

        barindex
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects zgRAT Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects zgRAT Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects zgRAT Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects NanoCore Author: ditekSHen
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NanoCore author = ditekSHen, description = Detects NanoCore
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
        Source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeCode function: 0_2_053B13080_2_053B1308
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeCode function: 0_2_053B13020_2_053B1302
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000000.249181724.0000000000A9A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameObjectHolderL.exe8 vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.292518005.0000000007700000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameDotNetZipAdditionalPlatforms.dllZ vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameDotNetZipAdditionalPlatforms.dllZ vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000004.00000000.277265474.00000000000DA000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameObjectHolderL.exe8 vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000005.00000000.283423330.0000000000F4A000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameObjectHolderL.exe8 vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeBinary or memory string: OriginalFilenameObjectHolderL.exe8 vs Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeVirustotal: Detection: 37%
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeReversingLabs: Detection: 43%
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile read: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJump to behavior
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe "C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe"
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.logJump to behavior
        Source: classification engineClassification label: mal100.troj.evad.winEXE@5/5@17/2
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Security.Principal.WindowsIdentity System.Security.Principal.WindowsIdentity::GetCurrent()
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csSecurity API names: System.Boolean System.Security.Principal.WindowsPrincipal::IsInRole(System.Security.Principal.WindowsBuiltInRole)
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeMutant created: \Sessions\1\BaseNamedObjects\Global\{fe56abb4-cb76-44f1-89b4-7bb11730ab9d}
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'TransformFinalBlock'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'TransformFinalBlock'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'CreateDecryptor'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqVxXNKnhAcArgJoGGYXiyyQu003du003d.csCryptographic APIs: 'TransformFinalBlock'
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

        Data Obfuscation

        barindex
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 0.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.a10000.0.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.a10000.0.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 4.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.50000.2.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 4.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.50000.1.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 4.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.50000.3.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 4.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.50000.0.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 4.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.50000.0.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.2.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.5.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.0.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.7.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.9.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.3.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.13.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.ec0000.11.unpack, Main.cs.Net Code: LateBinding.LateCall(V_0, null, "Invoke", new object[] { null, new object[] { "49456E756D556E6B6E", "6642354E56715A62", "TexasHoldem" } }, null, null)
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeCode function: 0_2_053B0006 push edx; retf 0002h0_2_053B009E
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeCode function: 0_2_053B6D70 pushfd ; retf 0_2_053B6D79
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeCode function: 0_2_053B6DB4 pushfd ; retf 0_2_053B6D79
        Source: initial sampleStatic PE information: section name: .text entropy: 7.91713576226
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
        Source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile created: \circular pssb parts disc credit term (dlr) may12 2022 (1).exe
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile created: \circular pssb parts disc credit term (dlr) may12 2022 (1).exe
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile created: \circular pssb parts disc credit term (dlr) may12 2022 (1).exeJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile created: \circular pssb parts disc credit term (dlr) may12 2022 (1).exeJump to behavior

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeFile opened: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe:Zone.Identifier read attributes | deleteJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information set: NOOPENFILEERRORBOXJump to behavior

        Malware Analysis System Evasion

        barindex
        Source: Yara matchFile source: 00000000.00000002.287715667.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTR
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287715667.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287715667.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe TID: 6320Thread sleep time: -45733s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe TID: 6336Thread sleep time: -922337203685477s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe TID: 6812Thread sleep time: -15679732462653109s >= -30000sJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWindow / User API: threadDelayed 5856Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWindow / User API: threadDelayed 3169Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWindow / User API: foregroundWindowGot 770Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWindow / User API: foregroundWindowGot 845Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeThread delayed: delay time: 45733Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess token adjusted: DebugJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeMemory allocated: page read and write | page guardJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeProcess created: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
        Source: C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: NanoCore.ClientPluginHost
        Source: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: NanoCore.ClientPluginHost
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40f52c0.6.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40a4ec0.8.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 0.2.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.40706a0.7.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe PID: 6648, type: MEMORYSTR
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid Accounts1
        Windows Management Instrumentation
        Path Interception11
        Process Injection
        1
        Masquerading
        OS Credential Dumping111
        Security Software Discovery
        Remote Services11
        Archive Collected Data
        Exfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        Disable or Modify Tools
        LSASS Memory1
        Process Discovery
        Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
        Non-Standard Port
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)21
        Virtualization/Sandbox Evasion
        Security Account Manager21
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
        Remote Access Software
        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)11
        Process Injection
        NTDS1
        Application Window Discovery
        Distributed Component Object ModelInput CaptureScheduled Transfer1
        Non-Application Layer Protocol
        SIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
        Deobfuscate/Decode Files or Information
        LSA Secrets12
        System Information Discovery
        SSHKeyloggingData Transfer Size Limits21
        Application Layer Protocol
        Manipulate Device CommunicationManipulate App Store Rankings or Ratings
        Replication Through Removable MediaLaunchdRc.commonRc.common1
        Hidden Files and Directories
        Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
        External Remote ServicesScheduled TaskStartup ItemsStartup Items2
        Obfuscated Files or Information
        DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
        Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job23
        Software Packing
        Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe38%VirustotalBrowse
        Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe44%ReversingLabsByteCode-MSIL.Trojan.FormBook
        Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe100%Joe Sandbox ML
        No Antivirus matches
        SourceDetectionScannerLabelLinkDownload
        5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.12.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
        5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.6.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
        5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.8.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
        5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.10.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
        5.0.Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe.400000.4.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
        SourceDetectionScannerLabelLink
        deranano2.ddns.net4%VirustotalBrowse
        SourceDetectionScannerLabelLink
        0%Avira URL Cloudsafe
        http://www.sajatypeworks.comiv;b0%Avira URL Cloudsafe
        http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
        http://www.founder.com.cn/cn?0%URL Reputationsafe
        http://www.sajatypeworks.com=0%Avira URL Cloudsafe
        http://www.tiro.com0%URL Reputationsafe
        http://www.fontbureau.comdko0%Avira URL Cloudsafe
        http://www.founder.com.cn/cn=0%URL Reputationsafe
        http://www.goodfont.co.kr0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/jp/;N0%Avira URL Cloudsafe
        http://www.sajatypeworks.com0%URL Reputationsafe
        http://www.typography.netD0%URL Reputationsafe
        http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/&N0%Avira URL Cloudsafe
        http://www.galapagosdesign.com/staff/dennis.htm0%URL Reputationsafe
        http://fontfabrik.com0%URL Reputationsafe
        http://www.fontbureau.comgrita0%URL Reputationsafe
        http://www.galapagosdesign.com/n0%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/CN0%Avira URL Cloudsafe
        http://www.fontbureau.comessedqN0%Avira URL Cloudsafe
        http://www.galapagosdesign.com/DPlease0%URL Reputationsafe
        http://www.sandoll.co.kr0%URL Reputationsafe
        http://www.urwpp.deDPlease0%URL Reputationsafe
        http://www.fontbureau.comasva0N0%Avira URL Cloudsafe
        http://www.zhongyicts.com.cn0%URL Reputationsafe
        http://www.fontbureau.comoJN0%Avira URL Cloudsafe
        http://www.sajatypeworks.come0%URL Reputationsafe
        http://www.sakkal.com0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/qN0%Avira URL Cloudsafe
        http://www.fontbureau.comalsd0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/gN0%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/)N0%Avira URL Cloudsafe
        http://www.fontbureau.comF0%URL Reputationsafe
        http://www.fontbureau.comnN70%Avira URL Cloudsafe
        http://www.sajatypeworks.comt0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/jp/0%URL Reputationsafe
        http://en.w0%URL Reputationsafe
        http://www.carterandcone.coml0%URL Reputationsafe
        http://www.fontbureau.comFgN0%Avira URL Cloudsafe
        http://www.founder.com.cn/cn0%URL Reputationsafe
        deranano2.ddns.net100%Avira URL Cloudmalware
        http://www.jiyu-kobo.co.jp/nN70%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/0%URL Reputationsafe
        http://www.fontbureau.como0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/JN0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        deranano2.ddns.net
        212.193.30.204
        truetrueunknown
        NameMaliciousAntivirus DetectionReputation
        true
        • Avira URL Cloud: safe
        low
        deranano2.ddns.nettrue
        • Avira URL Cloud: malware
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://www.fontbureau.com/designersGCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
          high
          http://www.sajatypeworks.comiv;bCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253293625.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          low
          http://www.fontbureau.com/designers/?Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://www.founder.com.cn/cn/bTheCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
            • URL Reputation: safe
            unknown
            http://www.fontbureau.com/designers?Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.fontbureau.com/designersBCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                http://www.founder.com.cn/cn?Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255166513.0000000005E07000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.sajatypeworks.com=Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252501913.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                low
                http://www.tiro.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.fontbureau.comdkoCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.fontbureau.com/designersCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  http://www.founder.com.cn/cn=Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255166513.0000000005E07000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.goodfont.co.krCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.jiyu-kobo.co.jp/jp/;NCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.sajatypeworks.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.typography.netDCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.founder.com.cn/cn/cTheCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.jiyu-kobo.co.jp/&NCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.galapagosdesign.com/staff/dennis.htmCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://fontfabrik.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.comgritaCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.galapagosdesign.com/nCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.264426212.0000000005E30000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.jiyu-kobo.co.jp/CNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.fontbureau.comessedqNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.galapagosdesign.com/DPleaseCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fonts.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://www.sandoll.co.krCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.urwpp.deDPleaseCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.fontbureau.comasva0NCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.zhongyicts.com.cnCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.fontbureau.comoJNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.sajatypeworks.comeCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253293625.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.sakkal.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.jiyu-kobo.co.jp/qNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.fontbureau.comalsdCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.jiyu-kobo.co.jp/gNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.apache.org/licenses/LICENSE-2.0Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      http://www.fontbureau.comCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.290816211.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.285453674.0000000005E00000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        http://www.jiyu-kobo.co.jp/)NCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.fontbureau.comFCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.fontbureau.comnN7Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.sajatypeworks.comtCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254274458.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255379018.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253520475.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253049894.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256782451.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253950954.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253752654.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256189334.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256383761.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252570710.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255631178.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256829217.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.256297123.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254074228.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255734900.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.254016281.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252501913.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253223324.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255015275.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252817530.0000000005E1B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.253605803.0000000005E1B000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.jiyu-kobo.co.jp/jp/Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://en.wCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.252732703.0000000005E06000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.carterandcone.comlCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.fontbureau.comFgNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.fontbureau.com/designers/cabarga.htmlNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.founder.com.cn/cnCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.255061936.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.com/designers/frere-jones.htmlCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://www.jiyu-kobo.co.jp/nN7Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.jiyu-kobo.co.jp/Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.fontbureau.comoCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262012669.0000000005E07000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.268407700.0000000005E0A000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.262424109.0000000005E08000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.fontbureau.com/designers8Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000002.291332241.0000000007102000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.jiyu-kobo.co.jp/JNCircular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257663249.0000000005E0B000.00000004.00000800.00020000.00000000.sdmp, Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, 00000000.00000003.257825537.0000000005E0B000.00000004.00000800.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              212.193.30.204
                              deranano2.ddns.netRussian Federation
                              57844SPD-NETTRtrue
                              IP
                              192.168.2.1
                              Joe Sandbox Version:34.0.0 Boulder Opal
                              Analysis ID:625814
                              Start date and time: 13/05/202208:06:102022-05-13 08:06:10 +02:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 10m 18s
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Sample file name:Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                              Cookbook file name:default.jbs
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:29
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:MAL
                              Classification:mal100.troj.evad.winEXE@5/5@17/2
                              EGA Information:
                              • Successful, ratio: 50%
                              HDC Information:
                              • Successful, ratio: 0.1% (good quality ratio 0.1%)
                              • Quality average: 62%
                              • Quality standard deviation: 8.5%
                              HCA Information:
                              • Successful, ratio: 99%
                              • Number of executed functions: 18
                              • Number of non-executed functions: 2
                              Cookbook Comments:
                              • Found application associated with file extension: .exe
                              • Adjust boot time
                              • Enable AMSI
                              • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                              • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, BackgroundTransferHost.exe, UpdateNotificationMgr.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, UsoClient.exe, wuapihost.exe
                              • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, fs.microsoft.com, go.microsoft.com, store-images.s-microsoft.com, login.live.com, sls.update.microsoft.com, ctldl.windowsupdate.com, settings-win.data.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                              • Execution Graph export aborted for target Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe, PID 6632 because there are no executed function
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                              TimeTypeDescription
                              08:07:24API Interceptor880x Sleep call for process: Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe modified
                              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                              212.193.30.204MARIAM HONAINE'S CV.exeGet hashmaliciousBrowse
                                QUOTATION.exeGet hashmaliciousBrowse
                                  2020574185.exeGet hashmaliciousBrowse
                                    ORDER.exeGet hashmaliciousBrowse
                                      POP.exeGet hashmaliciousBrowse
                                        Bill Of Lading.exeGet hashmaliciousBrowse
                                          900010225 CON.LUMES JAIPUR 05.02.2022.exeGet hashmaliciousBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                            deranano2.ddns.netMARIAM HONAINE'S CV.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            QUOTATION.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            2020574185.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            ORDER.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            POP.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            Bill Of Lading.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            900010225 CON.LUMES JAIPUR 05.02.2022.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            FYI.exeGet hashmaliciousBrowse
                                            • 194.31.98.18
                                            FYI.exeGet hashmaliciousBrowse
                                            • 194.31.98.18
                                            VOLGOIL LLC SOFT CORPORATE OFFER VESSEL TO TANK.exeGet hashmaliciousBrowse
                                            • 194.31.98.18
                                            product specification and detailspdf.exeGet hashmaliciousBrowse
                                            • 194.31.98.18
                                            MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                            SPD-NETTRNew Purchase Order 4522028497676.xlsxGet hashmaliciousBrowse
                                            • 212.193.30.214
                                            MARIAM HONAINE'S CV.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            QUOTATION.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            Resetter.exeGet hashmaliciousBrowse
                                            • 212.193.30.29
                                            SecuriteInfo.com.Trojan.PackedNET.331.26146.exeGet hashmaliciousBrowse
                                            • 212.193.30.38
                                            hdk8Z67C7x.exeGet hashmaliciousBrowse
                                            • 212.193.30.29
                                            CHANGE OF ACCOUNT RUSH TO DESK.exeGet hashmaliciousBrowse
                                            • 212.193.30.101
                                            2020574185.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            ORDER.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            ckc238HATk.exeGet hashmaliciousBrowse
                                            • 212.193.30.45
                                            ckc238HATk.exeGet hashmaliciousBrowse
                                            • 212.193.30.45
                                            TjDCLiM89x.exeGet hashmaliciousBrowse
                                            • 212.193.30.45
                                            POP.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            AFAC7896CF21983233C533EEAEC870610856969D98218.exeGet hashmaliciousBrowse
                                            • 212.193.30.29
                                            E4FB57012D7A31E6511C4BAC952323093E8BB51F13884.exeGet hashmaliciousBrowse
                                            • 212.193.30.29
                                            E2E7294A6FEE9EF6372897F3BEBFFB0D17BC31B9CF8C6.exeGet hashmaliciousBrowse
                                            • 212.193.30.29
                                            Bill Of Lading.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            900010225 CON.LUMES JAIPUR 05.02.2022.exeGet hashmaliciousBrowse
                                            • 212.193.30.204
                                            7nSmJgc4Js.exeGet hashmaliciousBrowse
                                            • 212.193.30.45
                                            arm7-20220427-0150Get hashmaliciousBrowse
                                            • 185.118.141.120
                                            No context
                                            No context
                                            Process:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File Type:ASCII text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):1308
                                            Entropy (8bit):5.345811588615766
                                            Encrypted:false
                                            SSDEEP:24:MLUE4K5E4Ks2E1qE4x84qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4FsXE8:MIHK5HKXE1qHxviYHKhQnoPtHoxHhAHJ
                                            MD5:EA78C102145ED608EF0E407B978AF339
                                            SHA1:66C9179ED9675B9271A97AB1FC878077E09AB731
                                            SHA-256:8BF01E0C445BD07C0B4EDC7199B7E17DAF1CA55CA52D4A6EAC4EF211C2B1A73E
                                            SHA-512:8C04139A1FC3C3BDACB680EC443615A43EB18E73B5A0CFCA644CB4A5E71746B275B3E238DD1A5A205405313E457BB75F9BBB93277C67AFA5D78DCFA30E5DA02B
                                            Malicious:true
                                            Reputation:moderate, very likely benign file
                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8d67d92724ba494b6c7fd089d6f25b48\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a
                                            Process:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):232
                                            Entropy (8bit):7.024371743172393
                                            Encrypted:false
                                            SSDEEP:6:X4LDAnybgCFcpJSQwP4d7ZrqJgTFwoaw+9XU4:X4LEnybgCFCtvd7ZrCgpwoaw+Z9
                                            MD5:32D0AAE13696FF7F8AF33B2D22451028
                                            SHA1:EF80C4E0DB2AE8EF288027C9D3518E6950B583A4
                                            SHA-256:5347661365E7AD2C1ACC27AB0D150FFA097D9246BB3626FCA06989E976E8DD29
                                            SHA-512:1D77FC13512C0DBC4EFD7A66ACB502481E4EFA0FB73D0C7D0942448A72B9B05BA1EA78DDF0BE966363C2E3122E0B631DB7630D044D08C1E1D32B9FB025C356A5
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.
                                            Process:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File Type:Non-ISO extended-ASCII text, with no line terminators
                                            Category:dropped
                                            Size (bytes):8
                                            Entropy (8bit):3.0
                                            Encrypted:false
                                            SSDEEP:3:LNln:LNl
                                            MD5:56ADDD7A30A64177C4CC87D0A61A3AEE
                                            SHA1:B857C6B80C8CC5D8FB92257F99398297103C6745
                                            SHA-256:2F0841CD881476437CBC932BBA028152B03666132DF48410C7DE4FAA183389F6
                                            SHA-512:A0A3CC6798AB662BBF2146ECD0653505BBF414F487C2AC37EAD1BB5CB68727A4FA0F8EEBA7BB000ECD788CED641C65DAD08AFBC13FE6270ABD1405CEDE84B918
                                            Malicious:true
                                            Reputation:low
                                            Preview:..dN.4.H
                                            Process:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):40
                                            Entropy (8bit):5.153055907333276
                                            Encrypted:false
                                            SSDEEP:3:9bzY6oRDT6P2bfVn1:RzWDT621
                                            MD5:4E5E92E2369688041CC82EF9650EDED2
                                            SHA1:15E44F2F3194EE232B44E9684163B6F66472C862
                                            SHA-256:F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48
                                            SHA-512:1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:9iH...}Z.4..f.~a........~.~.......3.U.
                                            Process:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):327432
                                            Entropy (8bit):7.99938831605763
                                            Encrypted:true
                                            SSDEEP:6144:oX44S90aTiB66x3Pl6nGV4bfD6wXPIZ9iBj0UeprGm2d7Tm:LkjYGsfGUc9iB4UeprKdnm
                                            MD5:7E8F4A764B981D5B82D1CC49D341E9C6
                                            SHA1:D9F0685A028FB219E1A6286AEFB7D6FCFC778B85
                                            SHA-256:0BD3AAC12623520C4E2031C8B96B4A154702F36F97F643158E91E987D317B480
                                            SHA-512:880E46504FCFB4B15B86B9D8087BA88E6C4950E433616EBB637799F42B081ABF6F07508943ECB1F786B2A89E751F5AE62D750BDCFFDDF535D600CF66EC44E926
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:pT..!..W..G.J..a.).@.i..wpK.so@...5.=.^..Q.oy.=e@9.B...F..09u"3.. 0t..RDn_4d.....E...i......~...|..fX_...Xf.p^......>a..$...e.6:7d.(a.A...=.)*.....{B.[...y%.*..i.Q.<..xt.X..H.. ..HF7g...I.*3.{.n....L.y;i..s-....(5i...........J.5b7}..fK..HV..,...0.... ....n.w6PMl.......v."".v.......#..X.a....../...cC...i..l{>5n.._+.e.d'...}...[..../...D.t..GVp.zz......(...o......b...+`J.{....hS1G.^*I..v&.jm.#u..1..Mg!.E..U.T.....6.2>...6.l.K.w"o..E..."K%{....z.7....<...,....]t.:.....[.Z.u...3X8.QI..j_.&..N..q.e.2...6.R.~..9.Bq..A.v.6.G..#y.....O....Z)G...w..E..k(....+..O..........Vg.2xC......O...jc.....z..~.P...q../.-.'.h.._.cj.=..B.x.Q9.pu.|i4...i...;O...n.?.,. ....v?.5}.OY@.dG|<.._[.69@.2..m..I..oP=...xrK.?............b..5....i&...l.c\b}..Q..O+.V.mJ.....pz....>F.......H...6$...d...|m...N..1.R..B.i..........$....$........CY}..$....r.....H...8...li.....7 P......?h....R.iF..6...q(.@LI.s..+K.....?m..H....*. l..&<}....`|.B....3.....I..o...u1..8i=.z.W..7
                                            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                            Entropy (8bit):7.908482488052613
                                            TrID:
                                            • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                            • Win32 Executable (generic) a (10002005/4) 49.78%
                                            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                            • Generic Win/DOS Executable (2004/3) 0.01%
                                            • DOS Executable Generic (2002/1) 0.01%
                                            File name:Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            File size:555520
                                            MD5:717fc8318eb370b1e8ae630af9fe431d
                                            SHA1:842ee97ed218857603188de6831afcc9919addd6
                                            SHA256:6035a6b2488b6c073d4b1cda9c9879e207b73e94c3551624667e59cc8719dd01
                                            SHA512:bcfcf0b516ada1d2d1eb7c4e50b99b060bfa1f3fa7e14e36541fb1106242afc2c6ea2921dc11992d0c5c00fc66cbe7600cd07d64f94cbaebc52e70d1a0c091f0
                                            SSDEEP:12288:Pp/rlgHiwwUkLzPOca+3Jr/m/O4EBSMF5puoyOkWKZWhJlQ:5p8ErNt/Wcu+kWtHlQ
                                            TLSH:46C4121B22A82BB2D1BA6BF920F2305603F2A5371523FF9D4DD930DA6D55B580710F2B
                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....}b..............0..p............... ........@.. ....................................@................................
                                            Icon Hash:00828e8e8686b000
                                            Entrypoint:0x488e0e
                                            Entrypoint Section:.text
                                            Digitally signed:false
                                            Imagebase:0x400000
                                            Subsystem:windows gui
                                            Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                                            DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                                            Time Stamp:0x627D08B8 [Thu May 12 13:16:40 2022 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:v4.0.30319
                                            OS Version Major:4
                                            OS Version Minor:0
                                            File Version Major:4
                                            File Version Minor:0
                                            Subsystem Version Major:4
                                            Subsystem Version Minor:0
                                            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                            Instruction
                                            jmp dword ptr [00402000h]
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax], al
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x88dbc0x4f.text
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x8a0000x5c4.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x8c0000xc.reloc
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x20000x86e140x87000False0.930960648148data7.91713576226IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                            .rsrc0x8a0000x5c40x600False0.42578125data4.13420959753IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            .reloc0x8c0000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountry
                                            RT_VERSION0x8a0900x334data
                                            RT_MANIFEST0x8a3d40x1eaXML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                            DLLImport
                                            mscoree.dll_CorExeMain
                                            DescriptionData
                                            Translation0x0000 0x04b0
                                            LegalCopyrightCopyright 2017
                                            Assembly Version1.0.0.0
                                            InternalNameObjectHolderL.exe
                                            FileVersion1.0.0.0
                                            CompanyName
                                            LegalTrademarks
                                            Comments
                                            ProductNameTexasHoldem
                                            ProductVersion1.0.0.0
                                            FileDescriptionTexasHoldem
                                            OriginalFilenameObjectHolderL.exe
                                            TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                            192.168.2.3212.193.30.2044975411872025019 05/13/22-08:08:00.468391TCP2025019ET TROJAN Possible NanoCore C2 60B497541187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985411872025019 05/13/22-08:09:21.317521TCP2025019ET TROJAN Possible NanoCore C2 60B498541187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044980111872025019 05/13/22-08:08:29.760918TCP2025019ET TROJAN Possible NanoCore C2 60B498011187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044982111872025019 05/13/22-08:08:42.572616TCP2025019ET TROJAN Possible NanoCore C2 60B498211187192.168.2.3212.193.30.204
                                            212.193.30.204192.168.2.31187497432841753 05/13/22-08:07:41.912295TCP2841753ETPRO TROJAN NanoCore RAT Keep-Alive Beacon (Inbound)118749743212.193.30.204192.168.2.3
                                            192.168.2.3212.193.30.2044975711872025019 05/13/22-08:08:08.371746TCP2025019ET TROJAN Possible NanoCore C2 60B497571187192.168.2.3212.193.30.204
                                            212.193.30.204192.168.2.31187497542810290 05/13/22-08:08:01.239966TCP2810290ETPRO TROJAN NanoCore RAT Keepalive Response 1118749754212.193.30.204192.168.2.3
                                            192.168.2.3212.193.30.2044982311872816766 05/13/22-08:08:50.618349TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498231187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044974211872816766 05/13/22-08:07:36.524732TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497421187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985211872816766 05/13/22-08:09:10.204690TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498521187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044974611872816766 05/13/22-08:07:48.002664TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497461187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975811872816766 05/13/22-08:08:17.137563TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497581187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044976811872816766 05/13/22-08:08:24.638697TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497681187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985311872816718 05/13/22-08:09:16.220396TCP2816718ETPRO TROJAN NanoCore RAT Keep-Alive Beacon498531187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044982311872025019 05/13/22-08:08:48.802408TCP2025019ET TROJAN Possible NanoCore C2 60B498231187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044974611872025019 05/13/22-08:07:47.181678TCP2025019ET TROJAN Possible NanoCore C2 60B497461187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044974211872025019 05/13/22-08:07:35.302011TCP2025019ET TROJAN Possible NanoCore C2 60B497421187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985211872025019 05/13/22-08:09:09.270895TCP2025019ET TROJAN Possible NanoCore C2 60B498521187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044980111872816766 05/13/22-08:08:30.710594TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498011187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975711872816766 05/13/22-08:08:10.114903TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497571187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044983311872025019 05/13/22-08:08:55.683074TCP2025019ET TROJAN Possible NanoCore C2 60B498331187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975411872816766 05/13/22-08:08:02.678142TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497541187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985311872025019 05/13/22-08:09:15.326471TCP2025019ET TROJAN Possible NanoCore C2 60B498531187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044982111872816766 05/13/22-08:08:43.505269TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498211187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044984811872816766 05/13/22-08:09:04.076097TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498481187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044974311872025019 05/13/22-08:07:41.882179TCP2025019ET TROJAN Possible NanoCore C2 60B497431187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044981511872816766 05/13/22-08:08:36.858197TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498151187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044985311872816766 05/13/22-08:09:16.220396TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498531187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975311872816766 05/13/22-08:07:55.099091TCP2816766ETPRO TROJAN NanoCore RAT CnC 7497531187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975311872025019 05/13/22-08:07:53.749457TCP2025019ET TROJAN Possible NanoCore C2 60B497531187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044976811872025019 05/13/22-08:08:23.663433TCP2025019ET TROJAN Possible NanoCore C2 60B497681187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044983311872816766 05/13/22-08:08:56.775852TCP2816766ETPRO TROJAN NanoCore RAT CnC 7498331187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975811872025019 05/13/22-08:08:15.665656TCP2025019ET TROJAN Possible NanoCore C2 60B497581187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044975811872816718 05/13/22-08:08:16.194877TCP2816718ETPRO TROJAN NanoCore RAT Keep-Alive Beacon497581187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044981511872025019 05/13/22-08:08:36.042332TCP2025019ET TROJAN Possible NanoCore C2 60B498151187192.168.2.3212.193.30.204
                                            192.168.2.3212.193.30.2044984811872025019 05/13/22-08:09:02.275060TCP2025019ET TROJAN Possible NanoCore C2 60B498481187192.168.2.3212.193.30.204
                                            TimestampSource PortDest PortSource IPDest IP
                                            May 13, 2022 08:07:35.189085960 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.217052937 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.217293024 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.302011013 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.371608973 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.395320892 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.424401999 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.529284000 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.615108013 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.788824081 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.886101007 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.947149038 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.947220087 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.947247028 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.947273970 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.947276115 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.947316885 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.975105047 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975169897 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975209951 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975250959 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975294113 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975332022 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975341082 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.975372076 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975394011 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:35.975410938 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:35.975564957 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.002994061 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003063917 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003103018 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003142118 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003170967 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003181934 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003217936 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003221035 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003262043 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003300905 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003305912 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003344059 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003365993 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003382921 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003422022 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003453016 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003460884 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003500938 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003514051 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003540039 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003577948 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003611088 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.003618002 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.003671885 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032332897 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032407999 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032450914 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032495022 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032526016 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032567024 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032609940 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032645941 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032650948 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032690048 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032691956 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032728910 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032768011 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032800913 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032805920 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032846928 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032857895 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032886982 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032898903 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.032926083 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.032967091 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033003092 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033011913 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033041954 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033067942 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033081055 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033118963 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033149004 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033157110 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033195019 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033207893 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033233881 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033277035 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033309937 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033313990 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033353090 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033375978 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033391953 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033430099 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033461094 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033468008 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033508062 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033530951 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033548117 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033587933 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033626080 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.033646107 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.033677101 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061475039 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061539888 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061584949 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061625004 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061640978 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061667919 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061709881 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061719894 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061750889 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061779976 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061791897 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061830997 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061862946 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061872959 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061913967 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061928988 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.061956882 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.061996937 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062017918 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062038898 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062077045 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062091112 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062118053 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062156916 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062192917 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062196016 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062236071 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062248945 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062278032 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062318087 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062350035 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062356949 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062395096 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062407970 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062433958 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062472105 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062506914 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062511921 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062553883 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062562943 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062592030 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062630892 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062664986 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062669992 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062707901 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062721014 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062748909 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062787056 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062819958 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062827110 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062868118 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062877893 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062906981 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062946081 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.062978983 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.062985897 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063023090 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063038111 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.063061953 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063100100 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063133001 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.063141108 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063182116 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063194036 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.063220978 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063260078 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063277006 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.063343048 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063380957 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063412905 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.063421011 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.063561916 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091145039 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091207027 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091244936 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091315985 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091356993 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091376066 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091393948 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091408968 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091434002 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091451883 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091473103 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091511011 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091545105 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091550112 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091588974 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091603994 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091628075 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091669083 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091701031 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091706038 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091744900 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091758966 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091784954 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091824055 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091856956 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091865063 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091902971 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091918945 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.091943026 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091984034 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.091996908 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092021942 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092062950 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092076063 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092102051 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092139959 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092154980 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092178106 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092217922 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092251062 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092257977 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092299938 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092310905 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092339039 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092376947 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092410088 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092416048 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092453003 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092474937 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092526913 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092569113 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092583895 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092606068 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092644930 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092655897 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092685938 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092722893 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092746973 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092761993 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092801094 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092802048 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092839003 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092889071 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092891932 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092906952 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092947006 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.092961073 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.092984915 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.093022108 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.093038082 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.093060970 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.093116999 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120256901 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120332003 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120371103 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120407104 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120409966 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120449066 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120460987 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120520115 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120562077 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120572090 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120604038 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120641947 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120660067 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120681047 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120721102 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120754957 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120758057 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120798111 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120815992 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120886087 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120910883 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120951891 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.120956898 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.120999098 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121011972 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121041059 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121082067 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121095896 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121136904 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121177912 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121179104 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121220112 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121258974 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121275902 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121304035 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121344090 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121385098 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121428013 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121467113 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121485949 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121500015 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121501923 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121517897 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121539116 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121579885 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121611118 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121619940 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121659994 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121694088 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121700048 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121746063 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121753931 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121786118 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121824980 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121838093 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121865034 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121912956 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121927023 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.121936083 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121975899 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.121988058 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.122015953 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122055054 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122088909 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.122095108 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122134924 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122157097 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.122184038 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122224092 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122237921 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.122265100 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.122327089 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.149714947 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149780035 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149823904 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.149837971 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149879932 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149916887 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149924994 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.149956942 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.149996996 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150028944 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150034904 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150077105 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150084972 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150125027 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150161982 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150182962 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150201082 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150239944 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150243998 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150279045 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150321960 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150333881 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150369883 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150393009 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150413036 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150433064 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150471926 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150511980 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150512934 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150554895 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150588989 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150598049 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150640011 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150650978 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150677919 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150717974 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150728941 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150758028 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150796890 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150806904 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150836945 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150876045 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150898933 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.150913954 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150960922 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.150984049 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151000023 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151038885 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151072025 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151077986 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151114941 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151128054 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151154995 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151194096 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151226044 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151232958 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151273012 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151299000 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151314020 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151354074 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151386976 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151391983 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151429892 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151442051 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151472092 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151496887 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151526928 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151536942 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151576042 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151606083 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151612997 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151650906 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151665926 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151690006 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151729107 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151757956 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151768923 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151828051 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.151885033 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151930094 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151968002 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.151978016 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.152007103 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152046919 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152060032 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.152086020 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152126074 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152137995 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.152168989 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152208090 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152221918 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.152245998 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152288914 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152298927 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.152328014 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:36.152379990 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.524732113 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:36.601154089 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:37.250981092 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:37.333664894 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:37.527476072 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:37.543832064 CEST118749742212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:37.543998003 CEST497421187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:41.851166010 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:41.878602028 CEST118749743212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:41.881591082 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:41.882179022 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:41.912295103 CEST118749743212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:41.962075949 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:41.989156961 CEST118749743212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:42.004565954 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:42.033258915 CEST118749743212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:42.090475082 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:42.569004059 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:42.589651108 CEST497431187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.142143965 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.169976950 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:47.170093060 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.181678057 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.251987934 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:47.252329111 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.280294895 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:47.384391069 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.659348011 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:47.739785910 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:47.970566988 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.002664089 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.030539989 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.087547064 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.315069914 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.396322012 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.396409035 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.424818993 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.587584019 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.617888927 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.775103092 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.791431904 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.880423069 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:48.887944937 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:48.974519014 CEST118749746212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:49.207058907 CEST497461187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:53.721395969 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:53.748831034 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:53.749036074 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:53.749456882 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:53.803994894 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:53.804265976 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:53.833164930 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:53.884916067 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.020106077 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.100018978 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.100265026 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.192826033 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.292644978 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.295058966 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.332011938 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.333169937 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.361139059 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.374428034 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.403599977 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.447468996 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:54.608795881 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:54.650667906 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:55.011168003 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:55.098963976 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:55.099091053 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:07:55.177109003 CEST118749753212.193.30.204192.168.2.3
                                            May 13, 2022 08:07:56.057840109 CEST497531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.437861919 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.467808008 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:00.467948914 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.468390942 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.538621902 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:00.539258003 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.567104101 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:00.619916916 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.791508913 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:00.869036913 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.029218912 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.073080063 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.104187965 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.133006096 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.209665060 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.212287903 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.239965916 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.241260052 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.269443989 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:01.323048115 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.647434950 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:01.739928961 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:02.678142071 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:02.729430914 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:02.791969061 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:02.867244959 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:02.943248987 CEST118749754212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:03.943905115 CEST497541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.343358994 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.370965004 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:08.371071100 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.371746063 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.421261072 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:08.491285086 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.520407915 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:08.589385033 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.711447954 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:08.786880970 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:08.971767902 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:09.050249100 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:09.052457094 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:09.080949068 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:09.082478046 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:09.110742092 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:09.110883951 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:09.138528109 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:09.276889086 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:10.114902973 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:10.192846060 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:10.344990015 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:10.427067995 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:10.836469889 CEST118749757212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:10.886492014 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:11.027652979 CEST497571187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:15.637177944 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:15.665009975 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:15.665623903 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:15.665656090 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:15.719175100 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:15.719624043 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:15.747514009 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:15.838274002 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.113182068 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.192917109 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.194876909 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.271138906 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.360537052 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.378336906 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.408068895 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.526808023 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.555278063 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.571094036 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:16.599770069 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:16.777503967 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:17.137562990 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:17.223952055 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:17.631160975 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:17.710031033 CEST118749758212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:18.168596029 CEST497581187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:23.631201982 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:23.660567045 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:23.661932945 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:23.663433075 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:23.702959061 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:23.703449965 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:23.731332064 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:23.965653896 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.376827002 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.452557087 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.638696909 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.640796900 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.666389942 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.666559935 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.730182886 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.876085043 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.906709909 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.907434940 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.937108994 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:24.938060999 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:24.971827984 CEST118749768212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:25.153306007 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:25.624880075 CEST497681187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:29.732378006 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:29.760006905 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:29.760154963 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:29.760917902 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:29.809751987 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:29.810332060 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:29.839529037 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:29.888010025 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:30.710593939 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:30.813860893 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.059535027 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.145905972 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.331316948 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.340989113 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.369456053 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.370953083 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.400460958 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.400602102 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.430212975 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.481884956 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.666104078 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.716737986 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:31.740858078 CEST118749801212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:31.740998030 CEST498011187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.013355017 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.040678978 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.041775942 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.042331934 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.109175920 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.109441996 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.137221098 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.294753075 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.628711939 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.708581924 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.858196974 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.904139042 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.905523062 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:36.934679031 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:36.936089993 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:37.240354061 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:37.240488052 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:37.294864893 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:37.322946072 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:37.794924021 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:37.826499939 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:37.828713894 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:37.904269934 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:37.931931973 CEST118749815212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:38.091800928 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:38.153107882 CEST498151187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:42.544550896 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:42.571962118 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:42.572179079 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:42.572616100 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:42.634898901 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:42.637363911 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:42.665213108 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:42.795373917 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:43.505269051 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:43.583250999 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:43.877108097 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:43.958750010 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:44.158596992 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:44.160392046 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:44.188862085 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:44.232937098 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:44.287873983 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:44.315614939 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:44.320405006 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:44.350920916 CEST118749821212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:44.404797077 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:44.553883076 CEST498211187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:48.760473013 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:48.787889004 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:48.788100958 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:48.802407980 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:48.867459059 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:48.867882967 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:48.896356106 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:48.952085972 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.199434996 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.286973000 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.498456955 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.499983072 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.527398109 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.577157021 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.590707064 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.677100897 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.906238079 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.952167988 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:49.979484081 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:49.987601995 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:50.015779972 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:50.015937090 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:50.044250965 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:50.092840910 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:50.161704063 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:50.255510092 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:50.618349075 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:50.708394051 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:51.381386042 CEST118749823212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:51.436732054 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:51.598146915 CEST498231187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.654515982 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.682387114 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:55.682493925 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.683073997 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.737241983 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:55.737346888 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.834041119 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:55.834141016 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:55.861922026 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:55.905817032 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.042253971 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.130184889 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.330420017 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.332377911 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.359503984 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.363461971 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.391335011 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.391509056 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.421319008 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.426351070 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.506810904 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:56.775851965 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:08:56.849323988 CEST118749833212.193.30.204192.168.2.3
                                            May 13, 2022 08:08:58.168776989 CEST498331187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:02.244868040 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:02.274483919 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:02.274580956 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:02.275059938 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:02.328269005 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:02.328628063 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:02.356767893 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:02.437696934 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.063185930 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.148144960 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.158971071 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.253868103 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.432281971 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.433285952 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.462435007 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.489253998 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.517210007 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.517484903 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.545717955 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.545809031 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:03.575727940 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:03.625287056 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:04.076097012 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:04.160180092 CEST118749848212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:05.070554018 CEST498481187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.242080927 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.269586086 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:09.269704103 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.270895004 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.333878040 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:09.334153891 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.365652084 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:09.406985998 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.709724903 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:09.785592079 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.012810946 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.013854027 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:10.044502020 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.045578957 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:10.073350906 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.073484898 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:10.106957912 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.107069016 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:10.194484949 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:10.204689980 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:10.287734032 CEST118749852212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:11.204633951 CEST498521187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.293801069 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.323955059 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.324074030 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.326471090 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.375271082 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.375718117 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.404839039 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.454324961 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.646147966 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.725939035 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.915699005 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.917701006 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.944910049 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.945952892 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:15.976754904 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:15.976939917 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:16.007033110 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:16.007148027 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:16.097681999 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:16.220396042 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:16.300637960 CEST118749853212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:17.252583027 CEST498531187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.289084911 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.316781998 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.316896915 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.317521095 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.365655899 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.365951061 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.393781900 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.394961119 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.488895893 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.687370062 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.688379049 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.717691898 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.718967915 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.747786045 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.747960091 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:21.779926062 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:21.830079079 CEST498541187192.168.2.3212.193.30.204
                                            May 13, 2022 08:09:23.841430902 CEST118749854212.193.30.204192.168.2.3
                                            May 13, 2022 08:09:23.892607927 CEST498541187192.168.2.3212.193.30.204
                                            TimestampSource PortDest PortSource IPDest IP
                                            May 13, 2022 08:07:35.158261061 CEST6485153192.168.2.38.8.8.8
                                            May 13, 2022 08:07:35.179594040 CEST53648518.8.8.8192.168.2.3
                                            May 13, 2022 08:07:41.831705093 CEST4931653192.168.2.38.8.8.8
                                            May 13, 2022 08:07:41.849618912 CEST53493168.8.8.8192.168.2.3
                                            May 13, 2022 08:07:47.056458950 CEST5592353192.168.2.38.8.8.8
                                            May 13, 2022 08:07:47.077611923 CEST53559238.8.8.8192.168.2.3
                                            May 13, 2022 08:07:53.702831984 CEST5742153192.168.2.38.8.8.8
                                            May 13, 2022 08:07:53.720316887 CEST53574218.8.8.8192.168.2.3
                                            May 13, 2022 08:08:00.358644009 CEST6535853192.168.2.38.8.8.8
                                            May 13, 2022 08:08:00.378106117 CEST53653588.8.8.8192.168.2.3
                                            May 13, 2022 08:08:08.322488070 CEST6526653192.168.2.38.8.8.8
                                            May 13, 2022 08:08:08.341821909 CEST53652668.8.8.8192.168.2.3
                                            May 13, 2022 08:08:15.610367060 CEST6333253192.168.2.38.8.8.8
                                            May 13, 2022 08:08:15.630654097 CEST53633328.8.8.8192.168.2.3
                                            May 13, 2022 08:08:23.610284090 CEST5298553192.168.2.38.8.8.8
                                            May 13, 2022 08:08:23.629914999 CEST53529858.8.8.8192.168.2.3
                                            May 13, 2022 08:08:29.710989952 CEST6064053192.168.2.38.8.8.8
                                            May 13, 2022 08:08:29.730588913 CEST53606408.8.8.8192.168.2.3
                                            May 13, 2022 08:08:35.992012024 CEST6187753192.168.2.38.8.8.8
                                            May 13, 2022 08:08:36.011658907 CEST53618778.8.8.8192.168.2.3
                                            May 13, 2022 08:08:42.522573948 CEST6441253192.168.2.38.8.8.8
                                            May 13, 2022 08:08:42.542064905 CEST53644128.8.8.8192.168.2.3
                                            May 13, 2022 08:08:48.737997055 CEST5177953192.168.2.38.8.8.8
                                            May 13, 2022 08:08:48.757751942 CEST53517798.8.8.8192.168.2.3
                                            May 13, 2022 08:08:55.632879972 CEST5060853192.168.2.38.8.8.8
                                            May 13, 2022 08:08:55.652250051 CEST53506088.8.8.8192.168.2.3
                                            May 13, 2022 08:09:02.216834068 CEST5420553192.168.2.38.8.8.8
                                            May 13, 2022 08:09:02.237754107 CEST53542058.8.8.8192.168.2.3
                                            May 13, 2022 08:09:09.219763041 CEST6275653192.168.2.38.8.8.8
                                            May 13, 2022 08:09:09.241046906 CEST53627568.8.8.8192.168.2.3
                                            May 13, 2022 08:09:15.269599915 CEST5849753192.168.2.38.8.8.8
                                            May 13, 2022 08:09:15.292433977 CEST53584978.8.8.8192.168.2.3
                                            May 13, 2022 08:09:21.268994093 CEST6270153192.168.2.38.8.8.8
                                            May 13, 2022 08:09:21.288356066 CEST53627018.8.8.8192.168.2.3
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                            May 13, 2022 08:07:35.158261061 CEST192.168.2.38.8.8.80x845aStandard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:07:41.831705093 CEST192.168.2.38.8.8.80xff8aStandard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:07:47.056458950 CEST192.168.2.38.8.8.80xac45Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:07:53.702831984 CEST192.168.2.38.8.8.80x78a3Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:00.358644009 CEST192.168.2.38.8.8.80x5137Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:08.322488070 CEST192.168.2.38.8.8.80xf172Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:15.610367060 CEST192.168.2.38.8.8.80x9690Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:23.610284090 CEST192.168.2.38.8.8.80x5d87Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:29.710989952 CEST192.168.2.38.8.8.80x302Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:35.992012024 CEST192.168.2.38.8.8.80x21abStandard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:42.522573948 CEST192.168.2.38.8.8.80x792Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:48.737997055 CEST192.168.2.38.8.8.80x5d0dStandard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:08:55.632879972 CEST192.168.2.38.8.8.80xde0Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:09:02.216834068 CEST192.168.2.38.8.8.80x1c63Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:09:09.219763041 CEST192.168.2.38.8.8.80x700Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:09:15.269599915 CEST192.168.2.38.8.8.80x45e2Standard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            May 13, 2022 08:09:21.268994093 CEST192.168.2.38.8.8.80xaeddStandard query (0)deranano2.ddns.netA (IP address)IN (0x0001)
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                            May 13, 2022 08:07:35.179594040 CEST8.8.8.8192.168.2.30x845aNo error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:07:41.849618912 CEST8.8.8.8192.168.2.30xff8aNo error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:07:47.077611923 CEST8.8.8.8192.168.2.30xac45No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:07:53.720316887 CEST8.8.8.8192.168.2.30x78a3No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:00.378106117 CEST8.8.8.8192.168.2.30x5137No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:08.341821909 CEST8.8.8.8192.168.2.30xf172No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:15.630654097 CEST8.8.8.8192.168.2.30x9690No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:23.629914999 CEST8.8.8.8192.168.2.30x5d87No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:29.730588913 CEST8.8.8.8192.168.2.30x302No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:36.011658907 CEST8.8.8.8192.168.2.30x21abNo error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:42.542064905 CEST8.8.8.8192.168.2.30x792No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:48.757751942 CEST8.8.8.8192.168.2.30x5d0dNo error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:08:55.652250051 CEST8.8.8.8192.168.2.30xde0No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:09:02.237754107 CEST8.8.8.8192.168.2.30x1c63No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:09:09.241046906 CEST8.8.8.8192.168.2.30x700No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:09:15.292433977 CEST8.8.8.8192.168.2.30x45e2No error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)
                                            May 13, 2022 08:09:21.288356066 CEST8.8.8.8192.168.2.30xaeddNo error (0)deranano2.ddns.net212.193.30.204A (IP address)IN (0x0001)

                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Click to jump to process

                                            Target ID:0
                                            Start time:08:07:13
                                            Start date:13/05/2022
                                            Path:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe"
                                            Imagebase:0xa10000
                                            File size:555520 bytes
                                            MD5 hash:717FC8318EB370B1E8AE630AF9FE431D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:.Net C# or VB.NET
                                            Yara matches:
                                            • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.287715667.0000000002E71000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.287825585.0000000002F03000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, Author: Florian Roth
                                            • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.289011583.0000000003FCC000.00000004.00000800.00020000.00000000.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                                            Reputation:low

                                            Target ID:4
                                            Start time:08:07:26
                                            Start date:13/05/2022
                                            Path:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            Imagebase:0x50000
                                            File size:555520 bytes
                                            MD5 hash:717FC8318EB370B1E8AE630AF9FE431D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            Target ID:5
                                            Start time:08:07:28
                                            Start date:13/05/2022
                                            Path:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Users\user\Desktop\Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).exe
                                            Imagebase:0xec0000
                                            File size:555520 bytes
                                            MD5 hash:717FC8318EB370B1E8AE630AF9FE431D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:.Net C# or VB.NET
                                            Yara matches:
                                            • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Florian Roth
                                            • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: NanoCore, Description: unknown, Source: 00000005.00000000.283132677.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                                            • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Florian Roth
                                            • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: NanoCore, Description: unknown, Source: 00000005.00000000.282158079.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                                            • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Florian Roth
                                            • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: NanoCore, Description: unknown, Source: 00000005.00000000.282584225.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                                            • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Florian Roth
                                            • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: NanoCore, Description: unknown, Source: 00000005.00000000.283785839.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                                            Reputation:low

                                            Reset < >

                                              Execution Graph

                                              Execution Coverage:15%
                                              Dynamic/Decrypted Code Coverage:100%
                                              Signature Coverage:0%
                                              Total number of Nodes:186
                                              Total number of Limit Nodes:10
                                              execution_graph 19253 53b500a 19254 53b5022 19253->19254 19255 53b4fc5 19253->19255 19256 53b511c 19254->19256 19257 53b5072 19254->19257 19258 53b06fc CallWindowProcW 19256->19258 19259 53b50ca CallWindowProcW 19257->19259 19260 53b5079 19257->19260 19258->19260 19259->19260 19114 53b2a78 19115 53b2ae0 CreateWindowExW 19114->19115 19117 53b2b9c 19115->19117 19261 53b78e8 19262 53b7915 19261->19262 19309 53b7344 19262->19309 19264 53b7936 19265 53b7344 2 API calls 19264->19265 19266 53b7968 19265->19266 19267 53b7344 2 API calls 19266->19267 19268 53b799a 19267->19268 19269 53b7344 2 API calls 19268->19269 19270 53b79cc 19269->19270 19271 53b7344 2 API calls 19270->19271 19272 53b79fe 19271->19272 19273 53b7344 2 API calls 19272->19273 19274 53b7a30 19273->19274 19275 53b7344 2 API calls 19274->19275 19276 53b7a62 19275->19276 19277 53b7344 2 API calls 19276->19277 19278 53b7a94 19277->19278 19279 53b7344 2 API calls 19278->19279 19280 53b7ac6 19279->19280 19281 53b7344 2 API calls 19280->19281 19282 53b7af8 19281->19282 19283 53b7344 2 API calls 19282->19283 19284 53b7b2a 19283->19284 19285 53b7344 2 API calls 19284->19285 19286 53b7b5c 19285->19286 19287 53b7344 2 API calls 19286->19287 19288 53b7bf2 19287->19288 19289 53b7344 2 API calls 19288->19289 19290 53b7c24 19289->19290 19291 53b7344 2 API calls 19290->19291 19292 53b7c56 19291->19292 19293 53b7344 2 API calls 19292->19293 19294 53b7c88 19293->19294 19295 53b7344 2 API calls 19294->19295 19296 53b7cec 19295->19296 19297 53b7344 2 API calls 19296->19297 19298 53b7d1e 19297->19298 19299 53b7344 2 API calls 19298->19299 19300 53b7d50 19299->19300 19314 53b74e4 19300->19314 19303 53b74e4 2 API calls 19304 53b7de6 19303->19304 19305 53b74e4 2 API calls 19304->19305 19306 53b7e18 19305->19306 19307 53b74e4 2 API calls 19306->19307 19308 53b7e4a 19307->19308 19310 53b734f 19309->19310 19311 53bb4db 19310->19311 19313 13b939c 2 API calls 19310->19313 19318 13b9e4d 19310->19318 19311->19264 19313->19311 19315 53b74ef 19314->19315 19317 53b7db4 19315->19317 19325 53b7634 19315->19325 19317->19303 19319 13b9e7b 19318->19319 19321 13ba0de 19319->19321 19322 53bbcb8 2 API calls 19319->19322 19323 53bbca8 2 API calls 19319->19323 19320 13ba11c 19320->19311 19321->19320 19324 13bdfd9 2 API calls 19321->19324 19322->19321 19323->19321 19324->19320 19326 53b763f 19325->19326 19328 13b9e4d 2 API calls 19326->19328 19329 13b939c 2 API calls 19326->19329 19327 53bc4e4 19327->19317 19328->19327 19329->19327 19118 135d01c 19119 135d034 19118->19119 19120 135d08e 19119->19120 19124 53b06fc 19119->19124 19128 53b2c30 19119->19128 19132 53b2c21 19119->19132 19125 53b0707 19124->19125 19127 53b3979 19125->19127 19136 53b0824 19125->19136 19129 53b2c56 19128->19129 19130 53b06fc CallWindowProcW 19129->19130 19131 53b2c77 19130->19131 19131->19120 19133 53b2c30 19132->19133 19134 53b06fc CallWindowProcW 19133->19134 19135 53b2c77 19134->19135 19135->19120 19137 53b082f 19136->19137 19138 53b50ca CallWindowProcW 19137->19138 19139 53b5079 19137->19139 19138->19139 19139->19127 19140 13be2b0 GetCurrentProcess 19141 13be32a GetCurrentThread 19140->19141 19142 13be323 19140->19142 19143 13be367 GetCurrentProcess 19141->19143 19144 13be360 19141->19144 19142->19141 19145 13be39d 19143->19145 19144->19143 19146 13be3c5 GetCurrentThreadId 19145->19146 19147 13be3f6 19146->19147 19148 13b40d0 19149 13b40e2 19148->19149 19150 13b40ee 19149->19150 19154 13b41e1 19149->19154 19159 13b3880 19150->19159 19152 13b410d 19155 13b4205 19154->19155 19163 13b42d1 19155->19163 19167 13b42e0 19155->19167 19160 13b388b 19159->19160 19175 13b5890 19160->19175 19162 13b6a50 19162->19152 19165 13b42e0 19163->19165 19164 13b43e4 19164->19164 19165->19164 19171 13b3e08 19165->19171 19169 13b4307 19167->19169 19168 13b43e4 19168->19168 19169->19168 19170 13b3e08 CreateActCtxA 19169->19170 19170->19168 19172 13b5370 CreateActCtxA 19171->19172 19174 13b5433 19172->19174 19176 13b589b 19175->19176 19179 13b700c 19176->19179 19178 13b97e5 19178->19162 19180 13b7017 19179->19180 19183 13b936c 19180->19183 19182 13b98c2 19182->19178 19184 13b9377 19183->19184 19187 13b939c 19184->19187 19186 13b99c2 19186->19182 19188 13b93a7 19187->19188 19190 13ba0de 19188->19190 19194 53bbcb8 19188->19194 19197 53bbca8 19188->19197 19189 13ba11c 19189->19186 19190->19189 19201 13bdfd9 19190->19201 19206 13bbfb8 19194->19206 19195 53bbcc6 19195->19190 19198 53bbcb8 19197->19198 19200 13bbfb8 2 API calls 19198->19200 19199 53bbcc6 19199->19190 19200->19199 19203 13be009 19201->19203 19202 13be02d 19202->19189 19203->19202 19226 13be198 19203->19226 19230 13be187 19203->19230 19207 13bbfc2 19206->19207 19208 13bbff3 19206->19208 19207->19208 19214 13bc250 19207->19214 19218 13bc240 19207->19218 19208->19195 19209 13bbfeb 19209->19208 19210 13bc1f0 GetModuleHandleW 19209->19210 19211 13bc21d 19210->19211 19211->19195 19215 13bc264 19214->19215 19217 13bc289 19215->19217 19222 13bb340 19215->19222 19217->19209 19219 13bc250 19218->19219 19220 13bb340 LoadLibraryExW 19219->19220 19221 13bc289 19219->19221 19220->19221 19221->19209 19223 13bc430 LoadLibraryExW 19222->19223 19225 13bc4a9 19223->19225 19225->19217 19227 13be1a5 19226->19227 19229 13be1df 19227->19229 19234 13bccbc 19227->19234 19229->19202 19231 13be198 19230->19231 19232 13be1df 19231->19232 19233 13bccbc 2 API calls 19231->19233 19232->19202 19233->19232 19235 13bccc7 19234->19235 19237 13beed8 19235->19237 19238 13be4d4 19235->19238 19237->19237 19239 13be4df 19238->19239 19240 13b939c 2 API calls 19239->19240 19241 13bef47 19240->19241 19244 53b0e40 19241->19244 19242 13bef80 19242->19237 19246 53b0e71 19244->19246 19247 53b0ebd 19244->19247 19245 53b0e7d 19245->19242 19246->19245 19248 53b12b2 LoadLibraryExW GetModuleHandleW 19246->19248 19249 53b12c0 LoadLibraryExW GetModuleHandleW 19246->19249 19247->19242 19248->19247 19249->19247 19250 13bbed0 19252 13bbfb8 2 API calls 19250->19252 19251 13bbedf 19252->19251 19330 13be8e0 DuplicateHandle 19331 13be976 19330->19331 19335 53b2cc0 SetWindowLongW 19336 53b2d2c 19335->19336

                                              Control-flow Graph

                                              APIs
                                              • GetCurrentProcess.KERNEL32 ref: 013BE310
                                              • GetCurrentThread.KERNEL32 ref: 013BE34D
                                              • GetCurrentProcess.KERNEL32 ref: 013BE38A
                                              • GetCurrentThreadId.KERNEL32 ref: 013BE3E3
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: Current$ProcessThread
                                              • String ID:
                                              • API String ID: 2063062207-0
                                              • Opcode ID: 8028fd92fcb2498e9aaae2257bcc815ed0a939eb4e30e45c8d83c00246966637
                                              • Instruction ID: 87a3669183d426e27ff8a1a5af6138ef39c368037a14373c043ec7974a5a1e46
                                              • Opcode Fuzzy Hash: 8028fd92fcb2498e9aaae2257bcc815ed0a939eb4e30e45c8d83c00246966637
                                              • Instruction Fuzzy Hash: 385194B0D042488FDB24CFA9DA88BDEBBF1EF48308F248569E549A7350D7755888CF65
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              APIs
                                              • GetCurrentProcess.KERNEL32 ref: 013BE310
                                              • GetCurrentThread.KERNEL32 ref: 013BE34D
                                              • GetCurrentProcess.KERNEL32 ref: 013BE38A
                                              • GetCurrentThreadId.KERNEL32 ref: 013BE3E3
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: Current$ProcessThread
                                              • String ID:
                                              • API String ID: 2063062207-0
                                              • Opcode ID: a1baaf97c826f1500014df2670e8caac0e7a539e8553a834bd9f1d55607eb5bc
                                              • Instruction ID: fa5d4af1db7b5c31d5c05df26e52f0a1edd319c35018dc60783cb8c7abbb7f02
                                              • Opcode Fuzzy Hash: a1baaf97c826f1500014df2670e8caac0e7a539e8553a834bd9f1d55607eb5bc
                                              • Instruction Fuzzy Hash: A75174B4D042498FDB24CFA9D688BDEBBF0EF48308F248469E559A7350D7749888CF65
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 778 13bbfb8-13bbfc0 779 13bc002-13bc00a 778->779 780 13bbfc2-13bbfdd call 13bb2dc 778->780 784 13bc00b-13bc04c 779->784 785 13bbfdf 780->785 786 13bbff3-13bbff7 780->786 791 13bc059-13bc067 784->791 792 13bc04e-13bc056 784->792 834 13bbfe5 call 13bc250 785->834 835 13bbfe5 call 13bc240 785->835 786->784 787 13bbff9 786->787 787->779 788 13bbfeb-13bbfed 788->786 790 13bc128-13bc1e8 788->790 829 13bc1ea-13bc1ed 790->829 830 13bc1f0-13bc21b GetModuleHandleW 790->830 793 13bc08b-13bc08d 791->793 794 13bc069-13bc06e 791->794 792->791 795 13bc090-13bc097 793->795 797 13bc079 794->797 798 13bc070-13bc077 call 13bb2e8 794->798 800 13bc099-13bc0a1 795->800 801 13bc0a4-13bc0ab 795->801 799 13bc07b-13bc089 797->799 798->799 799->795 800->801 804 13bc0b8-13bc0c1 call 13bb2f8 801->804 805 13bc0ad-13bc0b5 801->805 810 13bc0ce-13bc0d3 804->810 811 13bc0c3-13bc0cb 804->811 805->804 813 13bc0f1-13bc0fe 810->813 814 13bc0d5-13bc0dc 810->814 811->810 820 13bc121-13bc127 813->820 821 13bc100-13bc11e 813->821 814->813 815 13bc0de-13bc0ee call 13bb308 call 13bb318 814->815 815->813 821->820 829->830 831 13bc21d-13bc223 830->831 832 13bc224-13bc238 830->832 831->832 834->788 835->788
                                              APIs
                                              • GetModuleHandleW.KERNELBASE(00000000), ref: 013BC20E
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: HandleModule
                                              • String ID:
                                              • API String ID: 4139908857-0
                                              • Opcode ID: 2e8554a23544196cdb4644befe6da3631ebf60054c47deca80c451b7921085d2
                                              • Instruction ID: 0b401dd8f0cfc3206bd8450cab7ee513be9730895983725159ed04be364c217c
                                              • Opcode Fuzzy Hash: 2e8554a23544196cdb4644befe6da3631ebf60054c47deca80c451b7921085d2
                                              • Instruction Fuzzy Hash: 2D813A70A00B058FD724CF69C48079ABBF1BF49208F008A2ED556D7A50E775E845CF91
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 836 53b2a78-53b2ade 837 53b2ae9-53b2af0 836->837 838 53b2ae0-53b2ae6 836->838 839 53b2afb-53b2b9a CreateWindowExW 837->839 840 53b2af2-53b2af8 837->840 838->837 842 53b2b9c-53b2ba2 839->842 843 53b2ba3-53b2bdb 839->843 840->839 842->843 847 53b2be8 843->847 848 53b2bdd-53b2be0 843->848 848->847
                                              APIs
                                              • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 053B2B8A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: CreateWindow
                                              • String ID:
                                              • API String ID: 716092398-0
                                              • Opcode ID: c0ed12fd2717a1b7d600a872d94411ea93f59b48b3066d894054155d93c0154a
                                              • Instruction ID: 757e1a720ca4f53a4d5b8b92154a8c2a12ee1da21243e615dfc20870224f9946
                                              • Opcode Fuzzy Hash: c0ed12fd2717a1b7d600a872d94411ea93f59b48b3066d894054155d93c0154a
                                              • Instruction Fuzzy Hash: C641C2B5D043099FDF14CF99C884ADEBBB5BF48310F24862AE919AB210D7B49885CF90
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 849 13b5364-13b5431 CreateActCtxA 851 13b543a-13b5494 849->851 852 13b5433-13b5439 849->852 859 13b54a3-13b54a7 851->859 860 13b5496-13b5499 851->860 852->851 861 13b54a9-13b54b5 859->861 862 13b54b8 859->862 860->859 861->862 864 13b54b9 862->864 864->864
                                              APIs
                                              • CreateActCtxA.KERNEL32(?), ref: 013B5421
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: Create
                                              • String ID:
                                              • API String ID: 2289755597-0
                                              • Opcode ID: 1c80ad774eb44a4c6c1c7364679bbade3e73215658b11b77ff0a2f24dd2b9bb5
                                              • Instruction ID: 83eb0fa2273d3e0826af521d11bf2f1b109b66b7409f3d0773ecd8a7f91b274b
                                              • Opcode Fuzzy Hash: 1c80ad774eb44a4c6c1c7364679bbade3e73215658b11b77ff0a2f24dd2b9bb5
                                              • Instruction Fuzzy Hash: 1F41E071D04718CFDB24CFA9C9847CEBBB5BF89308F24806AD519AB250DB75694ACF90
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 865 53b0824-53b506c 868 53b511c-53b513c call 53b06fc 865->868 869 53b5072-53b5077 865->869 876 53b513f-53b514c 868->876 871 53b50ca-53b5102 CallWindowProcW 869->871 872 53b5079-53b50b0 869->872 874 53b510b-53b511a 871->874 875 53b5104-53b510a 871->875 878 53b50b9-53b50c8 872->878 879 53b50b2-53b50b8 872->879 874->876 875->874 878->876 879->878
                                              APIs
                                              • CallWindowProcW.USER32(?,?,?,?,?), ref: 053B50F1
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: CallProcWindow
                                              • String ID:
                                              • API String ID: 2714655100-0
                                              • Opcode ID: f41813c781434616e2bc95cbb6e5fbad8c80daa8c34e92a990ef910aa84adea9
                                              • Instruction ID: 3112e35077f102bbb1fbc0a7e39d14d0e5a83ea206a81c60b157c35d0bb36fbf
                                              • Opcode Fuzzy Hash: f41813c781434616e2bc95cbb6e5fbad8c80daa8c34e92a990ef910aa84adea9
                                              • Instruction Fuzzy Hash: 29415AB8A002059FDB14CF89C488BAAFBF5FF88314F15C859D919A7721D3B5A945CFA0
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 882 13b3e08-13b5431 CreateActCtxA 885 13b543a-13b5494 882->885 886 13b5433-13b5439 882->886 893 13b54a3-13b54a7 885->893 894 13b5496-13b5499 885->894 886->885 895 13b54a9-13b54b5 893->895 896 13b54b8 893->896 894->893 895->896 898 13b54b9 896->898 898->898
                                              APIs
                                              • CreateActCtxA.KERNEL32(?), ref: 013B5421
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: Create
                                              • String ID:
                                              • API String ID: 2289755597-0
                                              • Opcode ID: a6d53e6e8c5fdbef43c02e12178a5f927a04136979d2242046e35fb857ca09dc
                                              • Instruction ID: 6c5a61a3a116183076b8177bb6bc0857408d0ad88cf2277a4773578fa794faf9
                                              • Opcode Fuzzy Hash: a6d53e6e8c5fdbef43c02e12178a5f927a04136979d2242046e35fb857ca09dc
                                              • Instruction Fuzzy Hash: C741D170D04718CBDB24CFA9C984BCEBBB5BF49308F248069D519BB251EBB56949CF90
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 899 13be8d8-13be8de 900 13be8e0-13be974 DuplicateHandle 899->900 901 13be97d-13be99a 900->901 902 13be976-13be97c 900->902 902->901
                                              APIs
                                              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 013BE967
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: DuplicateHandle
                                              • String ID:
                                              • API String ID: 3793708945-0
                                              • Opcode ID: 5c0381046d2895ee369761ab7d679274c5b93f574ef9dc5254310af8eb4cb1e9
                                              • Instruction ID: b3b3b5ba0f610957d5b30428220fb562a2e1d584b954a2ed5d3ee2969c1c9c28
                                              • Opcode Fuzzy Hash: 5c0381046d2895ee369761ab7d679274c5b93f574ef9dc5254310af8eb4cb1e9
                                              • Instruction Fuzzy Hash: 6621E6B5D00208AFDB10CF99D584ADEFBF8FB48324F14852AE955A3310D379A954CFA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 905 13be8e0-13be974 DuplicateHandle 906 13be97d-13be99a 905->906 907 13be976-13be97c 905->907 907->906
                                              APIs
                                              • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 013BE967
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: DuplicateHandle
                                              • String ID:
                                              • API String ID: 3793708945-0
                                              • Opcode ID: af4cadf1977e3000deaf40040ebb67bd510f6c9306bc5c5e3e78f2eb7dfbeada
                                              • Instruction ID: bdc57c172ec0c078705667a87230c6e442b70d9006bf9376e014d9695343af9d
                                              • Opcode Fuzzy Hash: af4cadf1977e3000deaf40040ebb67bd510f6c9306bc5c5e3e78f2eb7dfbeada
                                              • Instruction Fuzzy Hash: 1021D8B5D042089FDB10CF99D584ADEFBF9FB48324F14841AE955A3310D378A954CFA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 910 13bc429-13bc470 911 13bc478-13bc4a7 LoadLibraryExW 910->911 912 13bc472-13bc475 910->912 913 13bc4a9-13bc4af 911->913 914 13bc4b0-13bc4cd 911->914 912->911 913->914
                                              APIs
                                              • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,013BC289,00000800,00000000,00000000), ref: 013BC49A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: 15875c1ec9fa011fce3ba751735aed7ce74c7377d3aff1ce1e2d49a910a7ee76
                                              • Instruction ID: a130a039df2179c67bfaf208f1356a88a4403db0fc4d58f7c9a116e0e6f2a3ce
                                              • Opcode Fuzzy Hash: 15875c1ec9fa011fce3ba751735aed7ce74c7377d3aff1ce1e2d49a910a7ee76
                                              • Instruction Fuzzy Hash: 631117B5D042089FDB20CFA9D484BEEFBF4AB48314F14852ED955B7600C379A545CFA5
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 917 13bb340-13bc470 919 13bc478-13bc4a7 LoadLibraryExW 917->919 920 13bc472-13bc475 917->920 921 13bc4a9-13bc4af 919->921 922 13bc4b0-13bc4cd 919->922 920->919 921->922
                                              APIs
                                              • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,013BC289,00000800,00000000,00000000), ref: 013BC49A
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: LibraryLoad
                                              • String ID:
                                              • API String ID: 1029625771-0
                                              • Opcode ID: 47e1f0e9e7105e483394e8769cb8eb80912bc32eca0e367837809f36c8518411
                                              • Instruction ID: 72dc08917ec1e7fa6469cdf4495b611b3786a513278cc21cbee076a380e3c68a
                                              • Opcode Fuzzy Hash: 47e1f0e9e7105e483394e8769cb8eb80912bc32eca0e367837809f36c8518411
                                              • Instruction Fuzzy Hash: E91106B59042089FDB20CF9AD484BEEFBF8AB88314F14842AD955B7600D378A645CFA5
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 925 13bc1a8-13bc1e8 926 13bc1ea-13bc1ed 925->926 927 13bc1f0-13bc21b GetModuleHandleW 925->927 926->927 928 13bc21d-13bc223 927->928 929 13bc224-13bc238 927->929 928->929
                                              APIs
                                              • GetModuleHandleW.KERNELBASE(00000000), ref: 013BC20E
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286935227.00000000013B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 013B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_13b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: HandleModule
                                              • String ID:
                                              • API String ID: 4139908857-0
                                              • Opcode ID: 63f638da43f29bcb2d07eaf76d5c1fa993c9caa83579f3810046b4ed84053499
                                              • Instruction ID: 5ecea6e5b6e5a4f5a1266441243cc4679cd101f263805896798cb95b5a499dee
                                              • Opcode Fuzzy Hash: 63f638da43f29bcb2d07eaf76d5c1fa993c9caa83579f3810046b4ed84053499
                                              • Instruction Fuzzy Hash: CC1102B5D002498FDB20CF9AD444BDEFBF8AB88224F14842AD919A7600D374A545CFA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 931 53b2cb9-53b2d2a SetWindowLongW 932 53b2d2c-53b2d32 931->932 933 53b2d33-53b2d47 931->933 932->933
                                              APIs
                                              • SetWindowLongW.USER32(?,?,?), ref: 053B2D1D
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: LongWindow
                                              • String ID:
                                              • API String ID: 1378638983-0
                                              • Opcode ID: 39d8e9a64bf1d6183e7f6a1059209353adbf584b8cf2238975f5b26f0ecc8e1b
                                              • Instruction ID: 0eba5f55f876e04d114b7b6f7b86ade38098a5e25754df44951e3ac08d42019e
                                              • Opcode Fuzzy Hash: 39d8e9a64bf1d6183e7f6a1059209353adbf584b8cf2238975f5b26f0ecc8e1b
                                              • Instruction Fuzzy Hash: F01118B59042498FDB20CF99D584BDFBBF8EF88324F14851AE955A7700C3B4A945CFA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 935 53b2cc0-53b2d2a SetWindowLongW 936 53b2d2c-53b2d32 935->936 937 53b2d33-53b2d47 935->937 936->937
                                              APIs
                                              • SetWindowLongW.USER32(?,?,?), ref: 053B2D1D
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID: LongWindow
                                              • String ID:
                                              • API String ID: 1378638983-0
                                              • Opcode ID: 5e7e422edfad9dfe3ac5bd75d80c9aade6e081bba2871febda095def438a6264
                                              • Instruction ID: 540959a7caf9b4eb5ae2f50e3e014108c63a0e0b7431b141f41f174bad12e14f
                                              • Opcode Fuzzy Hash: 5e7e422edfad9dfe3ac5bd75d80c9aade6e081bba2871febda095def438a6264
                                              • Instruction Fuzzy Hash: B211D3B59042099FDB10CF99D584BDEBBF8EB48324F14851AE955A7700C3B4A944CFA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286820192.000000000135D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0135D000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_135d000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b87d95fe2242fdb607f2627c4403f086dae91c1fb1efe9821ae4c5525e88ed71
                                              • Instruction ID: 8eba9bdc51defaf5a0351a9a9169b04db1e7dfbb5b3896b6a3bdfc4374d5bd15
                                              • Opcode Fuzzy Hash: b87d95fe2242fdb607f2627c4403f086dae91c1fb1efe9821ae4c5525e88ed71
                                              • Instruction Fuzzy Hash: 3F2122B5508204EFDB41CF94D9C0F26BBA5FB84768F24CA6DED094B242C336D846CA61
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286820192.000000000135D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0135D000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_135d000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7f6d59377eb4cec3abfdc9142adb3547070b79068b4e6dd3f2e70725d0187258
                                              • Instruction ID: 77676d828b72ded2eb2bb6d3aeac3ba24c6c3555ef88268f76848d301b0c7dca
                                              • Opcode Fuzzy Hash: 7f6d59377eb4cec3abfdc9142adb3547070b79068b4e6dd3f2e70725d0187258
                                              • Instruction Fuzzy Hash: 272130B4508204DFCB50CF94D8C0F26BB65FB84768F24C969ED0A4B246C33AD846CAA1
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286820192.000000000135D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0135D000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_135d000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 847d21315161970f8b4243043daccdbd09c1f14298f94b1571dd323cfa0b7f02
                                              • Instruction ID: 9330e42f20a76d80698089ad5eda8ebe1f4cb2cffb4e2352e4cfff5c85c96ca9
                                              • Opcode Fuzzy Hash: 847d21315161970f8b4243043daccdbd09c1f14298f94b1571dd323cfa0b7f02
                                              • Instruction Fuzzy Hash: E221A1755093808FDB03CF24D990B15BF71EB46218F28C5EAD8498B697C33AD84ACB62
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.286820192.000000000135D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0135D000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_135d000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 419e88c0e41451e1777907f29bf01e173359922e2c53350f3ed2aa1ddc1fa567
                                              • Instruction ID: e7173be50949acb5021bee655f400113d964159c6c25f6d48fc8e1eff3b28131
                                              • Opcode Fuzzy Hash: 419e88c0e41451e1777907f29bf01e173359922e2c53350f3ed2aa1ddc1fa567
                                              • Instruction Fuzzy Hash: 0011BB75904280DFCB42CF54D5C0B15BBB1FB84628F28C6ADDC494B656C33AD44ACB61
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 19c5fc5a6b1ce96761ef1a8aeb3e60e841d5ecc4e351f6d77afcd5a340f1abee
                                              • Instruction ID: 31110a019514aa82019dc4daa4c1ff8200ae223bcc5a641e9e76cedccd4623a2
                                              • Opcode Fuzzy Hash: 19c5fc5a6b1ce96761ef1a8aeb3e60e841d5ecc4e351f6d77afcd5a340f1abee
                                              • Instruction Fuzzy Hash: 4A1291F1ED17469AD310CF65E8983A93BA1B7443ACBD0CB08D2621BAD1D7B4196ECF44
                                              Uniqueness

                                              Uniqueness Score: -1.00%

                                              Memory Dump Source
                                              • Source File: 00000000.00000002.289790878.00000000053B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 053B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_53b0000_Circular PSSB Parts Disc Credit Term (Dlr) May12 2022 (1).jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cb8a1025cda8873f7280dfa6a5be854464aa302832f6942c04f4d6b22f48227e
                                              • Instruction ID: 4bc6b7001556912d901b814e7d9e746e22fb2adb660d376fa6fcce6d5550016b
                                              • Opcode Fuzzy Hash: cb8a1025cda8873f7280dfa6a5be854464aa302832f6942c04f4d6b22f48227e
                                              • Instruction Fuzzy Hash: 36C11AB1E917458AD710CF65E8883993BB1BB843ACF91CB08D1622FAD1D7B4186ECF44
                                              Uniqueness

                                              Uniqueness Score: -1.00%